What the vulnerability does
01Description
Unauthenticated Broken Access Control in Content Control <= 2.6.5 versions.
CVSS base score
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
What the vulnerability does
Unauthenticated Broken Access Control in Content Control <= 2.6.5 versions.
Explanation of Vulnerability in Simple Terms
Content Control through version 2.6.5 fails to properly check user permissions before allowing access to sensitive functions. An unauthenticated attacker can read limited information from the site without needing to log in or interact with a victim. Update to a version newer than 2.6.5.
What an attacker can do
Read limited non-public information from the site without authentication.
Potential impact on your site
Unauthorized users can access sensitive data that should be restricted to authenticated administrators.
Conditions required to exploit
Network access to the site; no authentication or user interaction required.
Key dates
External resources
Related vulnerabilities