What the vulnerability does
01Description
Unauthenticated Broken Access Control in Qubely <= 1.8.14 versions.
CVSS base score
CVSS vector
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N
What the vulnerability does
Unauthenticated Broken Access Control in Qubely <= 1.8.14 versions.
Explanation of Vulnerability in Simple Terms
Qubely versions up to 1.8.14 lack proper authorization checks, allowing unauthenticated attackers to read and modify limited data through network requests. The vulnerability requires specific conditions to exploit and has low impact on confidentiality and integrity. No authentication is needed, but attack complexity is high.
What an attacker can do
Read and modify limited data without authentication.
Potential impact on your site
Unauthorized users may access or alter sensitive information depending on what data Qubely exposes.
Conditions required to exploit
Network access; no authentication required, but specific conditions must be met.
Key dates
External resources
Related vulnerabilities