What the vulnerability does
01Description
Subscriber Broken Access Control in Solace Extra <= 1.6.0 versions.
CVSS base score
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:H
What the vulnerability does
Subscriber Broken Access Control in Solace Extra <= 1.6.0 versions.
Explanation of Vulnerability in Simple Terms
Solace Extra versions up to 1.6.0 lack proper authorization checks, allowing authenticated users with low privileges to modify site data and cause service disruptions. An attacker with a basic user account can bypass access controls to alter content or disable functionality. The vulnerability requires valid login credentials but no special interaction from victims.
What an attacker can do
Modify site content and disable functionality without proper permission.
Potential impact on your site
Unauthorized users can alter or delete content and cause site downtime.
Conditions required to exploit
Valid user account with low privileges; network access to the site.
Key dates
External resources
Related vulnerabilities