Missing Authorization Vulnerability Affects NextMove Lite
CVE-2024-25092
8.8HIGH
Summary
A missing authorization vulnerability has been identified in XLPlugins NextMove Lite, which could allow unauthorized users to execute actions that should be restricted. This issue impacts all versions from the initial release through version 2.17.0, posing significant risks to user data and application integrity. Organizations using NextMove Lite should assess their security measures and update to a patched version to mitigate risks associated with this vulnerability.
Affected Version(s)
NextMove Lite <= 2.17.0
References
EPSS Score
66% chance of being exploited in the next 30 days.
CVSS V3.1
Score:
8.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved
Credit
Yudistira Arya (Patchstack Alliance)