What the vulnerability does
01Description
Subscriber Broken Access Control in Frontend Admin by DynamiApps <= 3.29.10 versions.
CVSS base score
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:H
What the vulnerability does
Subscriber Broken Access Control in Frontend Admin by DynamiApps <= 3.29.10 versions.
Explanation of Vulnerability in Simple Terms
Frontend Admin by DynamiApps versions up to 3.29.10 lack proper authorization checks, allowing authenticated users to modify site content and disrupt service availability. An attacker with low-level access can bypass intended restrictions to alter data or cause the site to become unavailable. No confidentiality breach occurs, but integrity and availability are at risk.
What an attacker can do
Modify site content and cause service disruption without proper authorization.
Potential impact on your site
Authenticated users can alter content and crash the site; you may lose data integrity and uptime.
Conditions required to exploit
Attacker must have a low-privilege user account on the site.
Key dates
External resources
Related vulnerabilities