What the vulnerability does
01Description
Missing Authorization vulnerability in nK DocsPress docspress allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects DocsPress: from n/a through <= 2.5.2.
CVSS base score
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
What the vulnerability does
Missing Authorization vulnerability in nK DocsPress docspress allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects DocsPress: from n/a through <= 2.5.2.
Explanation of Vulnerability in Simple Terms
DocsPress versions up to 2.5.2 lack proper authorization checks, allowing authenticated users with low privileges to read sensitive information they should not access. The vulnerability requires a valid user account but no special interaction. Update to version 2.5.3 or later to resolve this issue.
What an attacker can do
Read sensitive information accessible only to higher-privileged users.
Potential impact on your site
Confidential data may be exposed to regular users or subscribers who should not have access.
Conditions required to exploit
Attacker must have a valid DocsPress user account with low privileges.
Key dates
External resources
Related vulnerabilities