Missing Authorization Security Levels Vulnerability
CVE-2023-27449
6.3MEDIUM
Summary
A significant vulnerability exists in Total Poll Lite by TotalSuite, which stems from a flaw in the access control mechanisms. This missing authorization issue allows unauthorized users to exploit incorrectly configured security levels, potentially gaining access to restricted features or data within the application. The vulnerability impacts various versions of Total Poll Lite, posing a risk to users who have not adequately secured their installations. It is imperative that users review their access control configurations to mitigate potential exploitation.
Affected Version(s)
Total Poll Lite <= 4.8.6
References
CVSS V3.1
Score:
6.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved
Credit
Mika (Patchstack Alliance)