Missing Authorization Vulnerability Affects Contest Gallery
CVE-2024-32778
8.5HIGH
Summary
A Missing Authorization vulnerability exists in Contest Gallery, impacting versions from n/a through 21.3.4. This flaw allows unauthorized users to perform actions that should be restricted, potentially leading to arbitrary file deletion or exposure of sensitive data. Users running affected versions are advised to implement security patches immediately to mitigate potential risks.
Affected Version(s)
Contest Gallery <= 21.3.4
References
CVSS V3.1
Score:
8.5
Severity:
HIGH
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Changed
Timeline
Vulnerability published
Vulnerability Reserved
Credit
CatFather (Patchstack Alliance)