What the vulnerability does
01Description
Missing Authorization vulnerability in NotFound Pie Register Premium. This issue affects Pie Register Premium: from n/a through 3.8.3.2.
CVSS base score
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
What the vulnerability does
Missing Authorization vulnerability in NotFound Pie Register Premium. This issue affects Pie Register Premium: from n/a through 3.8.3.2.
Explanation of Vulnerability in Simple Terms
Pie Register Premium versions up to 3.8.3.2 lack proper authorization checks, allowing authenticated users to access sensitive information they should not be able to view. An attacker with a low-privilege account can read data belonging to other users or the site. The vulnerability requires an existing user account but no additional user interaction.
What an attacker can do
Read sensitive data or information belonging to other users on the site.
Potential impact on your site
User data may be exposed to other registered users; privacy and data confidentiality are at risk.
Conditions required to exploit
Attacker must have a valid low-privilege user account on the site.
Key dates
External resources
Related vulnerabilities