What the vulnerability does
01Description
Subscriber Broken Access Control in AnsPress – Question and answer 4.4.4 versions.
CVSS base score
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:L
What the vulnerability does
Subscriber Broken Access Control in AnsPress – Question and answer 4.4.4 versions.
Explanation of Vulnerability in Simple Terms
AnsPress versions 4.4.4 and earlier lack proper authorization checks, allowing authenticated users to modify content they should not have access to. An attacker with a low-privilege account can alter or delete questions, answers, or other site data. The vulnerability affects the integrity of user-generated content and site availability.
What an attacker can do
Modify or delete questions, answers, and other content without proper permission.
Potential impact on your site
Users' posts can be altered or removed by other low-privilege accounts, damaging site trust and data integrity.
Conditions required to exploit
Attacker must have a registered user account on the site.
Key dates
External resources
Related vulnerabilities