What the vulnerability does
01Description
Missing Authorization vulnerability in RedNao Smart Forms.This issue affects Smart Forms: from n/a through 2.6.91.
CVSS base score
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N
What the vulnerability does
Missing Authorization vulnerability in RedNao Smart Forms.This issue affects Smart Forms: from n/a through 2.6.91.
Explanation of Vulnerability in Simple Terms
Smart Forms versions up to 2.6.91 lack proper authorization checks, allowing authenticated users to modify form data they should not have access to. An attacker with a low-privilege account can alter form submissions or settings belonging to other users or forms. The vulnerability requires valid login credentials but no additional user interaction. Update to a version newer than 2.6.91.
What an attacker can do
Modify form data or settings belonging to other users or forms.
Potential impact on your site
Authenticated users can tamper with forms and submissions outside their intended scope.
Conditions required to exploit
Valid login credentials with low-level site access.
Key dates
External resources
Related vulnerabilities