What the vulnerability does
01Description
Improper Privilege Management vulnerability in AA-Team WZone allows Privilege Escalation.This issue affects WZone: from n/a through 14.0.10.
CVSS base score
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
What the vulnerability does
Improper Privilege Management vulnerability in AA-Team WZone allows Privilege Escalation.This issue affects WZone: from n/a through 14.0.10.
Explanation of Vulnerability in Simple Terms
WZone versions up to 14.0.10 contain a privilege management flaw that allows authenticated users with low-level access to read sensitive data, modify site content, or disrupt service. An attacker needs a valid user account but no special permissions to exploit this vulnerability. Sites running affected versions should update immediately.
What an attacker can do
Read sensitive data, modify content, or disrupt service availability on the site.
Potential impact on your site
Any authenticated user can access or modify data and functionality they should not have permission to use.
Conditions required to exploit
Attacker must have a valid user account with low-level privileges; no user interaction required.
Key dates
External resources
Related vulnerabilities