What the vulnerability does
01Description
Missing Authorization vulnerability in Ateeq Rafeeq RepairBuddy computer-repair-shop allows Privilege Escalation.This issue affects RepairBuddy: from n/a through <= 3.8119.
CVSS base score
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
What the vulnerability does
Missing Authorization vulnerability in Ateeq Rafeeq RepairBuddy computer-repair-shop allows Privilege Escalation.This issue affects RepairBuddy: from n/a through <= 3.8119.
Explanation of Vulnerability in Simple Terms
RepairBuddy versions 3.8119 and earlier lack proper authorization checks, allowing authenticated users with low privileges to read, modify, or delete sensitive data and functionality. An attacker with a basic user account can perform actions restricted to administrators without additional authentication. This affects all data confidentiality, integrity, and system availability.
What an attacker can do
Read, modify, or delete sensitive data and perform admin-level actions with a low-privilege user account.
Potential impact on your site
Any registered user can access and modify critical site data, user accounts, and settings reserved for administrators.
Conditions required to exploit
Attacker must have a valid low-privilege user account on the site; no additional user interaction required.
Key dates
External resources
Related vulnerabilities