What the vulnerability does
01Description
Missing Authorization vulnerability in TotalSuite Total Poll Lite.This issue affects Total Poll Lite: from n/a through 4.9.9.
CVSS base score
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L
What the vulnerability does
Missing Authorization vulnerability in TotalSuite Total Poll Lite.This issue affects Total Poll Lite: from n/a through 4.9.9.
Explanation of Vulnerability in Simple Terms
Total Poll Lite versions up to 4.9.9 lack proper authorization checks, allowing authenticated users to trigger a denial-of-service condition. An attacker with low-level site access can make requests that degrade site availability. The vulnerability requires valid login credentials and does not affect data confidentiality or integrity.
What an attacker can do
Degrade site availability by triggering resource exhaustion or service disruption.
Potential impact on your site
Authenticated users can cause temporary site slowdowns or unavailability without elevated permissions.
Conditions required to exploit
Attacker must have a valid user account with low-level privileges on the site.
Key dates
External resources
Related vulnerabilities