What the vulnerability does
01Description
Missing Authorization vulnerability in Saul Morales Pacheco Donate visa donate-visa allows Stored XSS.This issue affects Donate visa: from n/a through <= 1.0.0.
CVSS base score
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L
What the vulnerability does
Missing Authorization vulnerability in Saul Morales Pacheco Donate visa donate-visa allows Stored XSS.This issue affects Donate visa: from n/a through <= 1.0.0.
Explanation of Vulnerability in Simple Terms
Donate visa version 1.0.0 and earlier lacks proper authorization checks, allowing authenticated users to perform actions they should not be permitted to perform. The vulnerability requires user interaction and can affect confidentiality, integrity, and availability of the application. A low-privileged user can exploit this to access or modify data beyond their intended scope.
What an attacker can do
An authenticated user can perform unauthorized actions affecting data confidentiality, integrity, or availability.
Potential impact on your site
Users with low-privilege accounts can access, modify, or disrupt functionality they should not have permission to use.
Conditions required to exploit
Attacker must have a low-privilege account and trick a user into clicking a malicious link or visiting a crafted page.
Key dates
External resources
Related vulnerabilities