What the vulnerability does
01Description
Incorrect Privilege Assignment vulnerability in SeventhQueen K Elements k-elements allows Privilege Escalation.This issue affects K Elements: from n/a through < 5.4.0.
CVSS base score
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
What the vulnerability does
Incorrect Privilege Assignment vulnerability in SeventhQueen K Elements k-elements allows Privilege Escalation.This issue affects K Elements: from n/a through < 5.4.0.
Explanation of Vulnerability in Simple Terms
K Elements versions 5.4.0 and earlier contain a privilege escalation vulnerability. An attacker with no authentication can read, modify, or delete sensitive data and disrupt site operations. The vulnerability requires only network access and no user interaction. Site administrators should update immediately to a version newer than 5.4.0.
What an attacker can do
Read, modify, or delete data and disrupt site operations without authentication.
Potential impact on your site
Attackers can compromise your site's data and availability without needing valid credentials.
Conditions required to exploit
Network access only; no authentication or user interaction required.
Key dates
External resources
Related vulnerabilities