What the vulnerability does
01Description
Subscriber Privilege Escalation in The Grid <= 2.7.9.1 versions.
CVSS base score
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
What the vulnerability does
Subscriber Privilege Escalation in The Grid <= 2.7.9.1 versions.
Explanation of Vulnerability in Simple Terms
The Grid through version 2.7.9.1 assigns excessive privileges to authenticated users, allowing them to read, modify, or delete sensitive data and disrupt site operations. An attacker with a low-privilege account can escalate their access without additional user interaction. Site administrators should update immediately to a version newer than 2.7.9.1.
What an attacker can do
Read, modify, or delete sensitive data; disrupt site availability with a low-privilege account.
Potential impact on your site
Unauthorized data access, modification, or deletion; potential site downtime if availability is compromised.
Conditions required to exploit
Attacker must have a valid low-privilege user account on the site.
Key dates
External resources
Related vulnerabilities