What the vulnerability does
01Description
Missing Authorization vulnerability in linethemes Nanosoft nanosoft allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Nanosoft: from n/a through < 1.3.2.
CVSS base score
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L
What the vulnerability does
Missing Authorization vulnerability in linethemes Nanosoft nanosoft allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Nanosoft: from n/a through < 1.3.2.
Explanation of Vulnerability in Simple Terms
Nanosoft versions 1.3.2 and earlier lack proper authorization checks, allowing authenticated users to modify data or disrupt service availability. An attacker with low-level access can bypass intended restrictions without user interaction. The vulnerability affects integrity and availability but not confidentiality.
What an attacker can do
Modify data or disrupt service availability without proper authorization.
Potential impact on your site
Authenticated users can tamper with site data or cause downtime beyond their intended permissions.
Conditions required to exploit
Attacker must have a low-privilege account on the system.
Key dates
External resources
Related vulnerabilities