What the vulnerability does
01Description
Incorrect Privilege Assignment vulnerability in WofficeIO Woffice woffice.This issue affects Woffice: from n/a through <= 5.4.10.
CVSS base score
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
What the vulnerability does
Incorrect Privilege Assignment vulnerability in WofficeIO Woffice woffice.This issue affects Woffice: from n/a through <= 5.4.10.
Explanation of Vulnerability in Simple Terms
Woffice versions up to 5.4.10 contain a privilege escalation vulnerability that allows unauthenticated attackers to gain full control of the application. The vulnerability stems from improper access control that fails to enforce authorization checks on sensitive operations. An attacker can read, modify, or delete any data and run their own code on the server without needing valid credentials.
What an attacker can do
Run code on the server, read all data, modify or delete files, and take full control of the application.
Potential impact on your site
Complete compromise of the Woffice installation and any data it stores; attackers can impersonate users and modify site content.
Conditions required to exploit
Network access only; no authentication or user interaction required.
Key dates
External resources
Related vulnerabilities