What the vulnerability does
01Description
Subscriber Broken Access Control in Ditty <= 3.1.67 versions.
CVSS base score
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
What the vulnerability does
Subscriber Broken Access Control in Ditty <= 3.1.67 versions.
Explanation of Vulnerability in Simple Terms
Ditty versions up to 3.1.67 lack proper authorization checks, allowing unauthenticated attackers to modify data through network requests. The vulnerability requires no user interaction and can be exploited remotely. Integrity of stored information is at risk, though confidentiality and availability are not directly impacted.
What an attacker can do
Modify data in Ditty without authentication or permission.
Potential impact on your site
Unauthorized changes to Ditty content or settings by anyone with network access.
Conditions required to exploit
Network access to the Ditty installation; no authentication required.
Key dates
External resources
Related vulnerabilities