What the vulnerability does
01Description
Editor Privilege Escalation in FluentCRM Pro <= 3.1.12 versions.
CVSS base score
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
What the vulnerability does
Editor Privilege Escalation in FluentCRM Pro <= 3.1.12 versions.
Explanation of Vulnerability in Simple Terms
FluentCRM Pro versions up to 3.1.12 contain a privilege assignment flaw that allows high-privileged users to access sensitive data and modify site functionality. An authenticated administrator can read confidential information, alter critical settings, and disrupt service availability. Update to a version newer than 3.1.12 to resolve this issue.
What an attacker can do
A high-privileged user can read sensitive data, modify site settings, and disrupt service availability.
Potential impact on your site
Administrators with compromised credentials could expose customer data, alter CRM configurations, or cause downtime.
Conditions required to exploit
Attacker must have high-level administrative privileges on the site; no user interaction required.
Key dates
External resources
Related vulnerabilities