What the vulnerability does
01Description
Missing Authorization vulnerability in WPPOOL FlexTable allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects FlexTable: from n/a through 3.24.0.
CVSS base score
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N
What the vulnerability does
Missing Authorization vulnerability in WPPOOL FlexTable allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects FlexTable: from n/a through 3.24.0.
Explanation of Vulnerability in Simple Terms
FlexTable through version 3.24.0 contains an authorization bypass that allows authenticated users to modify data they should not have access to. An attacker with low-level site access can alter records without proper permission checks. The vulnerability affects integrity but not confidentiality or availability.
What an attacker can do
Modify or alter data in FlexTable without proper authorization checks.
Potential impact on your site
Authenticated users can modify FlexTable records beyond their intended permissions, risking data integrity.
Conditions required to exploit
Attacker must have a low-privilege authenticated account on the site.
Key dates
External resources
Related vulnerabilities