What the vulnerability does
01Description
Missing Authorization vulnerability in reputeinfosystems ARForms arforms.This issue affects ARForms: from n/a through <= 6.4.
CVSS base score
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:H
What the vulnerability does
Missing Authorization vulnerability in reputeinfosystems ARForms arforms.This issue affects ARForms: from n/a through <= 6.4.
Explanation of Vulnerability in Simple Terms
ARForms versions 6.4 and earlier lack proper authorization checks, allowing authenticated users to modify data and disrupt site operations. An attacker with a low-privilege account can bypass access controls to alter form submissions or configuration. The vulnerability affects integrity and availability but not confidentiality. Update to a version newer than 6.4.
What an attacker can do
Modify form data and disrupt site availability with a low-privilege user account.
Potential impact on your site
Form data can be altered or deleted by unauthorized users; site availability may be compromised.
Conditions required to exploit
Attacker must have a valid user account with low-level privileges on the site.
Key dates
External resources
Related vulnerabilities