What the vulnerability does
01Description
Missing Authorization vulnerability in dugudlabs Eyewear prescription form eyewear-prescription-form allows Privilege Escalation.This issue affects Eyewear prescription form: from n/a through <= 4.0.18.
CVSS base score
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
What the vulnerability does
Missing Authorization vulnerability in dugudlabs Eyewear prescription form eyewear-prescription-form allows Privilege Escalation.This issue affects Eyewear prescription form: from n/a through <= 4.0.18.
Explanation of Vulnerability in Simple Terms
The Eyewear prescription form through version 4.0.18 lacks authorization checks on sensitive operations. An unauthenticated attacker can read, modify, or delete prescription data and other records without any credentials. This affects all installations unless patched.
What an attacker can do
Read, modify, or delete prescription records and other data without logging in.
Potential impact on your site
Patient prescription data and other records can be accessed, altered, or destroyed by anyone on the internet.
Conditions required to exploit
Network access to the form; no authentication or user interaction required.
Key dates
External resources
Related vulnerabilities