What the vulnerability does
01Description
Missing Authorization vulnerability in weDevs weDocs wedocs allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects weDocs: from n/a through <= 2.1.18.
CVSS base score
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
What the vulnerability does
Missing Authorization vulnerability in weDevs weDocs wedocs allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects weDocs: from n/a through <= 2.1.18.
Explanation of Vulnerability in Simple Terms
weDocs through version 2.1.18 fails to properly check user permissions before allowing access to certain functionality. An attacker without authentication can read sensitive information from the site. Update to version 2.3.0 or later to resolve this issue.
What an attacker can do
Read sensitive information without logging in.
Potential impact on your site
Unauthorized users can access confidential data stored in weDocs.
Conditions required to exploit
Network access to the site; no authentication or user interaction required.
Key dates
External resources
Related vulnerabilities