Access Control Vulnerability in ARMember Premium by Repute InfoSystems
CVE-2023-39994
4.3MEDIUM
Summary
A vulnerability exists within Repute InfoSystems' ARMember Premium that allows for improper access control due to missing authorization checks. This flaw can be exploited by attackers to gain unauthorized access to user features and sensitive data, compromising the integrity of user permissions. The issue primarily affects versions of ARMember Premium from not available (n/a) through 5.9.2, necessitating immediate awareness and action from users to ensure their systems are configured securely.
Affected Version(s)
ARMember Premium <= 5.9.2
References
CVSS V3.1
Score:
4.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved
Credit
Cat (Patchstack Alliance)