What the vulnerability does
01Description
Missing Authorization vulnerability in reputeinfosystems ARForms arforms.This issue affects ARForms: from n/a through <= 6.4.
CVSS base score
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:H
What the vulnerability does
Missing Authorization vulnerability in reputeinfosystems ARForms arforms.This issue affects ARForms: from n/a through <= 6.4.
Explanation of Vulnerability in Simple Terms
ARForms versions 6.4 and earlier lack proper authorization checks, allowing authenticated users with low privileges to modify data and disrupt site availability. An attacker with a basic user account can bypass access controls to alter form submissions or configurations. Sites running affected versions should update immediately to restore proper permission enforcement.
What an attacker can do
Modify form data and configurations, or cause the site to become unavailable.
Potential impact on your site
Unauthorized users can tamper with form submissions and cause service disruptions.
Conditions required to exploit
Attacker needs a low-privilege user account on the site; no user interaction required.
Key dates
External resources
Related vulnerabilities