What the vulnerability does
01Description
Missing Authorization vulnerability in pietro MobiLoud allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects MobiLoud: from n/a through 4.6.5.
CVSS base score
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H
What the vulnerability does
Missing Authorization vulnerability in pietro MobiLoud allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects MobiLoud: from n/a through 4.6.5.
Explanation of Vulnerability in Simple Terms
MobiLoud versions up to 4.6.5 lack proper authorization checks, allowing authenticated users to modify or delete data they should not have access to. An attacker with a low-privilege account can escalate their capabilities within the application. No confidentiality impact occurs, but integrity and availability of data are at risk.
What an attacker can do
Modify or delete data belonging to other users or the application without proper authorization.
Potential impact on your site
Authenticated users can tamper with or destroy data they should not be able to access, compromising data integrity.
Conditions required to exploit
Attacker must have a valid low-privilege user account; no user interaction required.
Key dates
External resources
Related vulnerabilities