Access Control Vulnerability in Crocoblock JetEngine by Crocoblock
CVE-2023-48758
7.1HIGH
Summary
Crocoblock JetEngine is associated with a vulnerability that arises from missing authorization mechanisms, specifically permitting exploitation through incorrectly configured access control security levels. This flaw may allow unauthorized access or manipulation of sensitive information within the JetEngine plugin. Affected versions include all prior to 3.2.4. Users are advised to assess their deployment and ensure compliance with best security practices to mitigate potential exploitation risks.
Affected Version(s)
JetEngine <= 3.2.4
References
CVSS V3.1
Score:
7.1
Severity:
HIGH
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved
Credit
Rafie Muhammad (Patchstack)