What the vulnerability does
01Description
Missing Authorization vulnerability in Crocoblock JetBlog jet-blog allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects JetBlog: from n/a through <= 2.4.7.
CVSS base score
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
What the vulnerability does
Missing Authorization vulnerability in Crocoblock JetBlog jet-blog allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects JetBlog: from n/a through <= 2.4.7.
Explanation of Vulnerability in Simple Terms
JetBlog through version 2.4.7 fails to properly check user permissions before allowing access to sensitive data. An authenticated user with low privileges can read information they should not have access to. The vulnerability does not allow modification or deletion of data, only unauthorized viewing. Update to a version newer than 2.4.7.
What an attacker can do
Read sensitive data they should not have access to based on their user role.
Potential impact on your site
Unauthorized users can view private or restricted content, potentially exposing sensitive information.
Conditions required to exploit
Attacker must have a low-privilege user account on the site; no user interaction required.
Key dates
External resources
Related vulnerabilities