What the vulnerability does
01Description
Incorrect Privilege Assignment vulnerability in Bowo Admin and Site Enhancements (ASE) admin-site-enhancements allows Privilege Escalation.This issue affects Admin and Site Enhancements (ASE): from n/a through <= 7.6.2.1.
Explanation of Vulnerability in Simple Terms
02Summary
Admin and Site Enhancements (ASE) versions 7.6.2.1 and earlier contain an improper privilege escalation vulnerability. An authenticated user with low privileges can gain high-level access to read, modify, or delete sensitive site data and functionality. The vulnerability requires specific attack conditions but poses significant risk to site integrity and confidentiality.
What an attacker can do
03Attacker Capabilities
Read, modify, or delete sensitive site data and functionality with elevated privileges.
Potential impact on your site
04Site Impact
Compromised user accounts could escalate to admin-level access, risking data theft, site defacement, or malware injection.
Conditions required to exploit
05Prerequisites
Attacker must have a low-privilege authenticated account; specific attack conditions required.
Key dates
06Disclosure timeline
February 4, 2025
CVE published
April 28, 2026
Record updated