What the vulnerability does
01Description
Unauthenticated Broken Access Control in Staff Training <= 1.0.7 versions.
CVSS base score
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L
What the vulnerability does
Unauthenticated Broken Access Control in Staff Training <= 1.0.7 versions.
Explanation of Vulnerability in Simple Terms
Staff Training versions up to 1.0.7 lack proper authorization checks, allowing unauthenticated attackers to read sensitive data, modify content, or disrupt service over the network. No special conditions or user interaction are required. Organizations using this product should update immediately to a patched version.
What an attacker can do
Read sensitive data, modify content, or disrupt service without logging in.
Potential impact on your site
Unauthorized users can access, modify, or disable training content and data without credentials.
Conditions required to exploit
Network access to the Staff Training application; no authentication required.
Key dates
External resources
Related vulnerabilities