Improper Privilege Management in Bold Page Builder - #VU20395
Published: August 26, 2019
Vulnerability identifier: #VU20395
CSH Severity: High
CVSS v4: 9.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: N/A
CWE-ID: CWE-269
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote attacker to escalate privilege on the target system.
The vulnerability exists due to the missing access controls. A remote attacker can perform actions that only an administrator should be allowed to do (e.g., modifying settings and importing data).
Affected software
Bold Page Builder
Remediation
Install updates from vendor's website.
Bold Page Builder - update to 2.3.2