profile-builder <= 3.11.8 - Unauthenticated Privilege Escalation
50Vexday Risk Score
Prioritize patching. It exploitation observed by VulnCheck.
ssvc Actcvss 9.8epss 0.8%
from disclosure to weapon
Published on NVDJul 31
VulnCheckJul 23
exploitation probability
0.8%top 47% of all CVEs
observed exploitation
yesVulnCheck
it's possible for an attacker to gain administrative access without having any kind of account on the targeted site and perform unauthorized actions. This is due to improper logic flow on the user registration process.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Affected products
Unknown · User Profile Builder