What the vulnerability does
01Description
Missing Authorization vulnerability in GRÜN Software Group GmbH GRÜN spendino Spendenformular spendino allows Privilege Escalation.This issue affects GRÜN spendino Spendenformular: from n/a through <= 1.0.1.
CVSS base score
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
What the vulnerability does
Missing Authorization vulnerability in GRÜN Software Group GmbH GRÜN spendino Spendenformular spendino allows Privilege Escalation.This issue affects GRÜN spendino Spendenformular: from n/a through <= 1.0.1.
Explanation of Vulnerability in Simple Terms
GRÜN spendino Spendenformular versions 1.0.1 and earlier lack authorization checks, allowing unauthenticated attackers to read, modify, or delete donation data without restriction. The vulnerability affects all versions from release through 1.0.1. No authentication or user interaction is required to exploit this flaw.
What an attacker can do
Read, modify, or delete donation records and sensitive data without any authentication.
Potential impact on your site
Attackers can access, alter, or destroy all donation data and records stored in the form.
Conditions required to exploit
Network access to the donation form; no authentication or user interaction required.
Key dates
External resources
Related vulnerabilities