Missing Authorization Vulnerability Affects Spectra
CVE-2023-36676
8.8HIGH
Summary
A missing authorization vulnerability exists in the Brainstorm Force Spectra Plugin, which could allow unauthorized access to restricted resources. This issue affects the Spectra Plugin in versions from n/a through 2.6.6. If exploited, attackers may potentially manipulate settings and access sensitive user data without proper verification. Implementing effective access control measures and updating to secured versions can help mitigate potential risks associated with this security flaw.
Affected Version(s)
Spectra <= 2.6.6
References
CVSS V3.1
Score:
8.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved
Credit
Rafie Muhammad (Patchstack)