What the vulnerability does
01Description
Improper Authentication vulnerability in Play.Ht allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects Play.Ht: from n/a through 3.6.4.
CVSS base score
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L
What the vulnerability does
Improper Authentication vulnerability in Play.Ht allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects Play.Ht: from n/a through 3.6.4.
Explanation of Vulnerability in Simple Terms
Play.ht versions up to 3.6.4 contain an authentication flaw that allows authenticated users to degrade service availability. An attacker with low-level account access can trigger a denial-of-service condition affecting the application's availability. The vulnerability requires valid credentials and network access but does not compromise data confidentiality or integrity.
What an attacker can do
An authenticated user can make the service unavailable or unresponsive to other users.
Potential impact on your site
Legitimate users may experience service interruptions or unavailability if an account is compromised or misused.
Conditions required to exploit
Attacker must have a valid Play.ht account with low-level privileges and network access.
Key dates
External resources
Related vulnerabilities