What the vulnerability does
01Description
Subscriber Broken Access Control in Service Finder Booking <= 6.2 versions.
CVSS base score
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
What the vulnerability does
Subscriber Broken Access Control in Service Finder Booking <= 6.2 versions.
Explanation of Vulnerability in Simple Terms
Service Finder Booking versions up to 6.2 lack proper authorization checks, allowing authenticated users to trigger a denial-of-service condition. An attacker with low-level account access can exhaust server resources without requiring user interaction. The vulnerability affects availability but not data confidentiality or integrity.
What an attacker can do
Authenticated user can crash or overload the site, making it unavailable to legitimate visitors.
Potential impact on your site
Site downtime or severe performance degradation if an authenticated user exploits this flaw.
Conditions required to exploit
Attacker must have a valid low-privilege account on the site; no user interaction required.
Key dates
External resources
Related vulnerabilities