What the vulnerability does
01Description
Missing Authorization vulnerability in Aspose.Cloud Marketplace Aspose.Words Exporter.This issue affects Aspose.Words Exporter: from n/a through 6.3.1.
CVSS base score
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
What the vulnerability does
Missing Authorization vulnerability in Aspose.Cloud Marketplace Aspose.Words Exporter.This issue affects Aspose.Words Exporter: from n/a through 6.3.1.
Explanation of Vulnerability in Simple Terms
Aspose.Words Exporter through version 6.3.1 does not properly check user permissions before allowing access to certain document export functions. A logged-in user with low privileges can read data they should not have access to. The vulnerability requires valid authentication but no special user interaction.
What an attacker can do
Read sensitive document data without proper authorization.
Potential impact on your site
Users' confidential documents may be exposed to other authenticated users with insufficient access controls.
Conditions required to exploit
Attacker must have a valid low-privilege account on the platform.
Key dates
External resources
Related vulnerabilities