What the vulnerability does
01Description
Authentication Bypass Using an Alternate Path or Channel vulnerability in NooTheme Jobica Core jobica-core allows Authentication Abuse.This issue affects Jobica Core: from n/a through <= 1.4.2.
CVSS base score
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
What the vulnerability does
Authentication Bypass Using an Alternate Path or Channel vulnerability in NooTheme Jobica Core jobica-core allows Authentication Abuse.This issue affects Jobica Core: from n/a through <= 1.4.2.
Explanation of Vulnerability in Simple Terms
Jobica Core versions up to 1.4.2 contain an authentication bypass vulnerability that allows unauthenticated attackers to gain full control of the application over the network. The vulnerability requires no user interaction and affects confidentiality, integrity, and availability. Site administrators should update immediately to a patched version.
What an attacker can do
Read, modify, or delete any data on the site without logging in.
Potential impact on your site
Complete compromise of the site and all user data without any warning or authentication.
Conditions required to exploit
Network access only; no authentication or user interaction required.
Key dates
External resources
Related vulnerabilities