What the vulnerability does
01Description
Missing Authorization vulnerability in Tagembed.This issue affects Tagembed: from n/a through 5.8.
CVSS base score
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L
What the vulnerability does
Missing Authorization vulnerability in Tagembed.This issue affects Tagembed: from n/a through 5.8.
Explanation of Vulnerability in Simple Terms
Tagembed versions 5.8 and earlier lack proper authorization checks, allowing authenticated users to modify or delete data they should not have access to. An attacker with a low-privilege account can change or remove content belonging to other users or the system. No confidentiality impact occurs, but integrity and availability of data are at risk.
What an attacker can do
Modify or delete data belonging to other users or the system.
Potential impact on your site
Authenticated users can tamper with or remove content they don't own, risking data loss and system integrity.
Conditions required to exploit
Attacker must have a valid low-privilege account on the Tagembed instance.
Key dates
External resources
Related vulnerabilities