What the vulnerability does
01Description
Subscriber Privilege Escalation in Service Finder Booking <= 6.2 versions.
CVSS base score
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
What the vulnerability does
Subscriber Privilege Escalation in Service Finder Booking <= 6.2 versions.
Explanation of Vulnerability in Simple Terms
Service Finder Booking versions up to 6.2 contain a privilege assignment flaw that allows authenticated users with low-level access to gain high-level permissions. An attacker can read sensitive data, modify site content, or disrupt service availability. The vulnerability requires a valid user account but no additional user interaction.
What an attacker can do
Read sensitive data, modify content, or disrupt site availability with escalated privileges.
Potential impact on your site
Any registered user can escalate their permissions to perform admin-level actions without authorization.
Conditions required to exploit
Attacker must have a valid low-privilege user account on the site.
Key dates
External resources
Related vulnerabilities