Missing Authorization Vulnerability Affects Hercules Core
CVE-2024-37232

8.8HIGH

Key Information:

Vendor
WordPress
Vendor
CVE Published:
1 November 2024

Summary

The Hercules Core product from Hercules Design has a vulnerability arising from missing authorization checks that impact the access control mechanisms. This issue may allow malicious users to exploit incorrectly configured security levels, enabling unauthorized changes and access to restricted functionalities. Versions of Hercules Core from n/a to 6.5 are specifically impacted, highlighting the importance of proper configuration and ongoing monitoring to safeguard against potential exploitation.

Affected Version(s)

Hercules Core <= 6.5

References

CVSS V3.1

Score:
8.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Dave Jong (Patchstack)
.