Missing Authorization Vulnerability in WP-CRM System
CVE-2024-55991
6.5MEDIUM
Summary
A critical missing authorization vulnerability has been identified in the WP-CRM System, which allows for exploitation of incorrectly configured access control settings. This misconfiguration can lead to unauthorized access to sensitive functionalities within the system. Affected versions include all prior to 3.2.9.1. Organizations using this software should prioritize a comprehensive review of their access control configurations to mitigate the risk of exploitation.
Affected Version(s)
WP-CRM System <= 3.2.9.1
References
CVSS V3.1
Score:
6.5
Severity:
MEDIUM
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved
Credit
Mika (Patchstack Alliance)