What the vulnerability does
01Description
Missing Authorization vulnerability in PropertyHive PropertyHive allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects PropertyHive: from n/a through 2.0.9.
CVSS base score
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
What the vulnerability does
Missing Authorization vulnerability in PropertyHive PropertyHive allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects PropertyHive: from n/a through 2.0.9.
Explanation of Vulnerability in Simple Terms
PropertyHive versions up to 2.0.9 fail to properly check user permissions before allowing access to certain data. A logged-in user with low privileges can read information they should not have access to. The vulnerability does not allow modification or deletion of data, only unauthorized viewing. Update to a version newer than 2.0.9 to resolve this issue.
What an attacker can do
Read data they should not have access to based on their user role.
Potential impact on your site
Sensitive information may be exposed to users with limited permissions, compromising data confidentiality.
Conditions required to exploit
Attacker must have a low-privilege account on the PropertyHive installation.
Key dates
External resources
Related vulnerabilities