What the vulnerability does
01Description
Missing Authorization vulnerability in AA-Team WZone woozone allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WZone: from n/a through <= 14.0.31.
CVSS base score
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L
What the vulnerability does
Missing Authorization vulnerability in AA-Team WZone woozone allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WZone: from n/a through <= 14.0.31.
Explanation of Vulnerability in Simple Terms
WZone versions 14.0.31 and earlier lack proper authorization checks, allowing authenticated users to modify data they should not have access to. An attacker with a low-privilege account can alter or disable functionality affecting other users or site operations. No confidentiality breach occurs, but integrity and availability are compromised.
What an attacker can do
Modify or disable data and functionality that should be restricted to higher-privilege users.
Potential impact on your site
Authenticated users can tamper with settings or data outside their intended permissions, risking data corruption and service disruption.
Conditions required to exploit
Attacker must have a valid low-privilege account on the site; no user interaction required.
Key dates
External resources
Related vulnerabilities