What the vulnerability does
01Description
Missing Authorization vulnerability in slui Media Hygiene media-hygiene allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Media Hygiene: from n/a through <= 4.0.1.
CVSS base score
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
What the vulnerability does
Missing Authorization vulnerability in slui Media Hygiene media-hygiene allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Media Hygiene: from n/a through <= 4.0.1.
Explanation of Vulnerability in Simple Terms
Media Hygiene versions 4.0.1 and earlier lack proper authorization checks, allowing authenticated users to read sensitive information they should not access. An attacker with a low-privilege account can view confidential data without additional interaction. The vulnerability affects the product across all versions from release through 4.0.1.
What an attacker can do
Read sensitive information accessible only to higher-privilege users.
Potential impact on your site
Confidential data may be exposed to any authenticated user, regardless of their role.
Conditions required to exploit
Attacker must have a valid low-privilege user account on the site.
Key dates
External resources
Related vulnerabilities