What the vulnerability does
01Description
Missing Authorization vulnerability in appsbd Vitepos.This issue affects Vitepos: from n/a through 3.0.1.
CVSS base score
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L
What the vulnerability does
Missing Authorization vulnerability in appsbd Vitepos.This issue affects Vitepos: from n/a through 3.0.1.
Explanation of Vulnerability in Simple Terms
Vitepos through version 3.0.1 lacks proper authorization checks, allowing authenticated users with low privileges to trigger a denial-of-service condition. An attacker with valid login credentials can make requests that degrade site availability. The vulnerability requires authentication but no special user interaction, making it a moderate risk for multi-user installations.
What an attacker can do
Authenticated user can degrade site availability by making specific requests.
Potential impact on your site
Legitimate users may experience service disruptions if an authenticated account is compromised or misused.
Conditions required to exploit
Valid login credentials with low-level user privileges; network access to the application.
Key dates
External resources
Related vulnerabilities