What the vulnerability does
01Description
Subscriber Privilege Escalation in Directories Pro <= 2.0.5 versions.
CVSS base score
CVSS vector
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:L
What the vulnerability does
Subscriber Privilege Escalation in Directories Pro <= 2.0.5 versions.
Explanation of Vulnerability in Simple Terms
Directories Pro through version 2.0.5 assigns incorrect privilege levels to user roles, allowing unauthenticated attackers to read and modify sensitive data. The vulnerability requires specific network conditions to exploit but does not require user interaction. Affected installations should update immediately to a version newer than 2.0.5.
What an attacker can do
Read and modify sensitive data without authentication by exploiting incorrect privilege assignment.
Potential impact on your site
Unauthorized users can access and alter directory data, compromising site integrity and confidentiality.
Conditions required to exploit
Network access to the site; specific attack complexity conditions must be met.
Key dates
External resources
Related vulnerabilities