What the vulnerability does
01Description
Broken Access Control vulnerability in ReviewX.This issue affects ReviewX: from n/a through 1.6.21.
CVSS base score
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N
What the vulnerability does
Broken Access Control vulnerability in ReviewX.This issue affects ReviewX: from n/a through 1.6.21.
Explanation of Vulnerability in Simple Terms
ReviewX versions up to 1.6.21 contain an integrity vulnerability allowing authenticated users to modify data they should not have access to. The vulnerability requires a valid user account and network access but no additional user interaction. The integrity impact is limited in scope. Current version 2.3.11 is not affected.
What an attacker can do
Modify data within the application without authorization.
Potential impact on your site
Users with basic accounts may alter data they shouldn't be able to change, compromising data integrity.
Conditions required to exploit
Attacker must have a valid ReviewX user account with low-level privileges.
Key dates
External resources