What the vulnerability does
01Description
Improper Privilege Management vulnerability in Booking Ultra Pro allows Privilege Escalation.This issue affects Booking Ultra Pro: from n/a through 1.1.12.
CVSS base score
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
What the vulnerability does
Improper Privilege Management vulnerability in Booking Ultra Pro allows Privilege Escalation.This issue affects Booking Ultra Pro: from n/a through 1.1.12.
Explanation of Vulnerability in Simple Terms
Booking Ultra Pro versions up to 1.1.12 contain a privilege management flaw that allows authenticated users with low-level access to perform actions reserved for higher-privilege roles. An attacker with a standard user account can read, modify, or delete sensitive data and disrupt site operations. Update to a version newer than 1.1.12 immediately.
What an attacker can do
Read, modify, or delete sensitive data and disrupt site operations using a low-privilege user account.
Potential impact on your site
Unauthorized users can access and alter booking data, user information, and site settings without proper authorization.
Conditions required to exploit
Attacker must have a valid low-privilege user account on the site; no user interaction required.
Key dates
External resources
Related vulnerabilities