What the vulnerability does
01Description
Subscriber Broken Access Control in Motors <= 1.4.113 versions.
CVSS base score
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N
What the vulnerability does
Subscriber Broken Access Control in Motors <= 1.4.113 versions.
Explanation of Vulnerability in Simple Terms
Stylemix Motors version 1.4.113 and earlier contains an authorization bypass that allows authenticated users to modify data they should not have access to. An attacker with a low-privilege account can change records without proper permission checks. The vulnerability affects the integrity of stored data but does not expose sensitive information or disrupt availability.
What an attacker can do
Modify or change data in the application without proper authorization.
Potential impact on your site
Unauthorized users can alter critical data, compromising data integrity and potentially affecting site functionality.
Conditions required to exploit
Attacker must have a valid low-privilege user account and network access to the application.
Key dates
External resources
Related vulnerabilities