What the vulnerability does
01Description
Missing Authorization vulnerability in Migrate Clone allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Clone: from n/a through 2.4.5.
CVSS base score
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N
What the vulnerability does
Missing Authorization vulnerability in Migrate Clone allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Clone: from n/a through 2.4.5.
Explanation of Vulnerability in Simple Terms
Migrate Clone versions up to 2.4.5 lack proper authorization checks, allowing authenticated users to modify content they should not have access to. An attacker with low-level account privileges can alter data integrity without administrative approval. The vulnerability affects the product's core functionality and requires an active user account to exploit.
What an attacker can do
Modify or alter content without proper authorization checks.
Potential impact on your site
Unauthorized users can alter site data, compromising content integrity and trust.
Conditions required to exploit
Attacker must have a low-privilege user account on the site.
Key dates
External resources
Related vulnerabilities