RealHomes Missing Authorization Vulnerability Affects Users
CVE-2023-37885
4.3MEDIUM
Summary
A vulnerability exists in InspiryThemes RealHomes due to missing authorization checks. This issue enables unauthorized users to gain access to restricted functionalities within the RealHomes theme. As a result, sensitive data may be exposed and manipulated. Affected versions include all releases from the earliest up to 4.0.2, necessitating immediate attention to patch this security flaw and safeguard against potential exploits.
Affected Version(s)
RealHomes <= 4.0.2
References
CVSS V3.1
Score:
4.3
Severity:
MEDIUM
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved
Credit
Dave Jong (Patchstack)