What the vulnerability does
01Description
Missing Authorization vulnerability in Brainstorm Force SureForms Pro allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects SureForms Pro: from n/a through 2.8.0.
CVSS base score
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L
What the vulnerability does
Missing Authorization vulnerability in Brainstorm Force SureForms Pro allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects SureForms Pro: from n/a through 2.8.0.
Explanation of Vulnerability in Simple Terms
SureForms Pro through version 2.8.0 fails to properly check user permissions before allowing access to certain functions. An attacker without authentication can read, modify, or delete data by sending direct requests to the application. This affects confidentiality, integrity, and availability of stored information.
What an attacker can do
Read, modify, or delete data without logging in or having permission.
Potential impact on your site
Unauthorized users can access, change, or remove form data and settings without credentials.
Conditions required to exploit
Network access to the SureForms Pro installation; no authentication required.
Key dates
External resources
Related vulnerabilities