What the vulnerability does
01Description
Incorrect Privilege Assignment vulnerability in Sirv CDN and Image Hosting Sirv sirv.This issue affects Sirv: from n/a through <= 7.2.2.
CVSS base score
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
What the vulnerability does
Incorrect Privilege Assignment vulnerability in Sirv CDN and Image Hosting Sirv sirv.This issue affects Sirv: from n/a through <= 7.2.2.
Explanation of Vulnerability in Simple Terms
Sirv versions up to 7.2.2 contain an authorization flaw that allows authenticated users to read, modify, or delete data they should not have access to. The vulnerability requires a valid user account but no special privileges. An attacker with low-level credentials can escalate their access to sensitive information and operations across the platform.
What an attacker can do
Read, modify, or delete data belonging to other users or accounts without authorization.
Potential impact on your site
User data, files, and account settings may be exposed, modified, or deleted by other authenticated users.
Conditions required to exploit
Attacker must have a valid Sirv user account with low-level privileges.
Key dates
External resources
Related vulnerabilities