What the vulnerability does
01Description
Unauthenticated Broken Access Control in Anti Spam and list cleaner – AcyChecker <= 2.0.0 versions.
CVSS base score
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L
What the vulnerability does
Unauthenticated Broken Access Control in Anti Spam and list cleaner – AcyChecker <= 2.0.0 versions.
Explanation of Vulnerability in Simple Terms
AcyChecker fails to properly check user permissions before allowing access to sensitive functions. An attacker with a low-privilege account can read, modify, or delete data without authorization. The vulnerability affects AcyChecker up to version 2.0.0. Update to a version newer than 2.0.0 when available.
What an attacker can do
Read, modify, or delete data without proper authorization using a low-privilege account.
Potential impact on your site
Unauthorized users can access and alter sensitive newsletter or subscriber data stored by AcyChecker.
Conditions required to exploit
Attacker must have a low-privilege user account on the site; no user interaction required.
Key dates
External resources
Related vulnerabilities