What the vulnerability does
01Description
Missing Authorization vulnerability in lowcage PegaPoll pegapoll allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects PegaPoll: from n/a through <= 1.0.2.
CVSS base score
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
What the vulnerability does
Missing Authorization vulnerability in lowcage PegaPoll pegapoll allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects PegaPoll: from n/a through <= 1.0.2.
Explanation of Vulnerability in Simple Terms
PegaPoll versions 1.0.2 and earlier lack authorization checks, allowing unauthenticated attackers to perform administrative actions over the network. An attacker can read, modify, or delete poll data and configuration without any credentials. This affects all installations of the affected versions.
What an attacker can do
Read, modify, or delete polls and poll data without logging in.
Potential impact on your site
Attackers can tamper with or destroy poll content and settings without any credentials.
Conditions required to exploit
Network access to the PegaPoll installation; no authentication or user interaction required.
Key dates
External resources
Related vulnerabilities