What the vulnerability does
01Description
Unauthenticated Broken Access Control in Total Upkeep <= 1.17.2 versions.
CVSS base score
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:H
What the vulnerability does
Unauthenticated Broken Access Control in Total Upkeep <= 1.17.2 versions.
Explanation of Vulnerability in Simple Terms
Total Upkeep through version 1.17.2 lacks proper authorization checks, allowing unauthenticated attackers to modify site data and cause service disruptions. The vulnerability requires no special access or user interaction. Site administrators should update immediately to a version newer than 1.17.2.
What an attacker can do
Modify site data and disrupt service availability without authentication.
Potential impact on your site
Attackers can alter site content and cause downtime without needing valid credentials.
Conditions required to exploit
Network access only; no authentication or user interaction required.
Key dates
External resources
Related vulnerabilities