What the vulnerability does
01Description
Missing Authorization vulnerability in ClickWhale ClickWhale clickwhale allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects ClickWhale: from n/a through <= 2.4.6.
CVSS base score
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L
What the vulnerability does
Missing Authorization vulnerability in ClickWhale ClickWhale clickwhale allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects ClickWhale: from n/a through <= 2.4.6.
Explanation of Vulnerability in Simple Terms
ClickWhale versions up to 2.4.6 lack proper authorization checks, allowing authenticated users to modify or disable site features they should not have access to. An attacker with low-level account privileges can alter integrity of the application without elevated permissions. The vulnerability requires valid login credentials but no additional user interaction.
What an attacker can do
Modify or disable site features without proper authorization.
Potential impact on your site
Authenticated users can alter application settings or disable features beyond their intended access level.
Conditions required to exploit
Valid ClickWhale user account with low-level privileges.
Key dates
External resources
Related vulnerabilities