CVE-2017-15680

MEDIUM6.5EPSS 0.92%

Missing Authorization in Crafter CMS

Published: 5/24/2022Modified: 11/8/2023

Description

In Crafter CMS Crafter Studio 3.0 prior to 3.0.1 an IDOR vulnerability exists which allows unauthenticated attackers to view and modify administrative data.

Affected packages (1)

CVSS scores

SourceVersionSeverityVector
osvCVSS 3.1MEDIUM6.5CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N

References (2)