Improper Privilege Management in Bold Page Builder - #VU20395

 

Improper Privilege Management in Bold Page Builder - #VU20395

Published: August 26, 2019


Vulnerability identifier: #VU20395
CSH Severity: High
CVSS v4: 9.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: N/A
CWE-ID: CWE-269
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to escalate privilege on the target system.

The vulnerability exists due to the missing access controls. A remote attacker can perform actions that only an administrator should be allowed to do (e.g., modifying settings and importing data).



Affected software

Bold Page Builder

Remediation

Install updates from vendor's website.

Bold Page Builder - update to 2.3.2

External References

Related Security Bulletins