What the vulnerability does
01Description
Incorrect Privilege Assignment vulnerability in NotFound Admin and Site Enhancements (ASE) Pro allows Privilege Escalation. This issue affects Admin and Site Enhancements (ASE) Pro: from n/a through 7.6.2.1.
CVSS base score
CVSS vector
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
What the vulnerability does
Incorrect Privilege Assignment vulnerability in NotFound Admin and Site Enhancements (ASE) Pro allows Privilege Escalation. This issue affects Admin and Site Enhancements (ASE) Pro: from n/a through 7.6.2.1.
Explanation of Vulnerability in Simple Terms
Admin and Site Enhancements (ASE) Pro versions up to 7.6.2.1 contain an authorization flaw that allows authenticated users with low privileges to read sensitive data, modify site content, or disrupt service. The vulnerability requires network access and low-level authentication but no user interaction. Administrators should update to a version newer than 7.6.2.1 immediately.
What an attacker can do
Read sensitive data, modify site content, or disrupt service availability on the affected site.
Potential impact on your site
Authenticated users with low privileges can access restricted functions, potentially compromising data integrity and site availability.
Conditions required to exploit
Attacker must have low-level authenticated access to the site; network access required.
Key dates
External resources
Related vulnerabilities