What the vulnerability does
01Description
Missing Authorization vulnerability in ProfileGrid User Profiles ProfileGrid allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects ProfileGrid: from n/a through 5.8.7.
CVSS base score
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N
What the vulnerability does
Missing Authorization vulnerability in ProfileGrid User Profiles ProfileGrid allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects ProfileGrid: from n/a through 5.8.7.
Explanation of Vulnerability in Simple Terms
ProfileGrid versions up to 5.8.7 lack proper authorization checks, allowing authenticated users to modify data they should not have access to. An attacker with a low-privilege account can alter information belonging to other users or the site. The vulnerability requires login but does not require user interaction beyond normal site usage.
What an attacker can do
Modify or alter data belonging to other users or the site without proper permission.
Potential impact on your site
User data integrity is at risk; any authenticated user can tamper with other users' profiles or settings.
Conditions required to exploit
Attacker must have a low-privilege account on the site; no user interaction required.
Key dates
External resources
Related vulnerabilities