Missing Authorization Vulnerability in QuantumCloud Floating Action Buttons
CVE-2024-56238
5.3MEDIUM
Summary
A missing authorization vulnerability exists in QuantumCloud's Floating Action Buttons plugin, allowing users to access functionalities that are not properly restricted by Access Control Lists (ACLs). This situation poses significant security risks as unauthorized users may exploit this oversight to execute actions beyond their intended privileges. The issue affects all versions of the Floating Action Buttons plugin up to and including version 0.9.1. Organizations are urged to review their implementations and apply updates or patches to mitigate potential threats stemming from this vulnerability.
Affected Version(s)
Floating Action Buttons <= 0.9.1
References
CVSS V3.1
Score:
5.3
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved
Credit
Mika (Patchstack Alliance)