What the vulnerability does
01Description
Client-Side Enforcement of Server-Side Security vulnerability in Highfivery LLC Zero Spam allows Removing Important Client Functionality.This issue affects Zero Spam: from n/a through 5.5.6.
CVSS base score
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
What the vulnerability does
Client-Side Enforcement of Server-Side Security vulnerability in Highfivery LLC Zero Spam allows Removing Important Client Functionality.This issue affects Zero Spam: from n/a through 5.5.6.
Explanation of Vulnerability in Simple Terms
Zero Spam versions up to 5.5.6 contain an integrity vulnerability that allows an attacker to modify data without authentication. The vulnerability requires only network access and no user interaction. Site administrators should update to a version newer than 5.5.6 to prevent unauthorized data modification.
What an attacker can do
Modify data on the site without logging in.
Potential impact on your site
Attackers can alter site content or settings without permission.
Conditions required to exploit
Network access only; no authentication or user interaction required.
Key dates
External resources
Related vulnerabilities