What the vulnerability does
01Description
Missing Authorization vulnerability in Gopi krishnan Fare Calculator fare-calculator allows Stored XSS.This issue affects Fare Calculator: from n/a through <= 1.1.
CVSS base score
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L
What the vulnerability does
Missing Authorization vulnerability in Gopi krishnan Fare Calculator fare-calculator allows Stored XSS.This issue affects Fare Calculator: from n/a through <= 1.1.
Explanation of Vulnerability in Simple Terms
Fare Calculator versions 1.1 and earlier lack proper authorization checks, allowing an attacker to perform unauthorized actions by tricking a user into visiting a malicious link. The vulnerability affects confidentiality, integrity, and availability of the application. Users should update to a version newer than 1.1 when available.
What an attacker can do
Perform unauthorized actions on behalf of a victim user who clicks a malicious link.
Potential impact on your site
Users' data and site functionality could be compromised if they interact with attacker-controlled links.
Conditions required to exploit
Victim must click an attacker-supplied link or visit a malicious page while logged in.
Key dates
External resources
Related vulnerabilities