PT-2024-36255 · Unknown · Zita Site Builder

Stealthcopter

·

Published

2024-12-16

·

Updated

2024-12-16

·

CVE-2024-54369

CVSS v3.1

9.1

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H
Name of the Vulnerable Software and Affected Versions: Zita Site Builder versions 1.0.2 and earlier
Description: The issue is related to a missing authorization vulnerability in Zita Site Builder, which allows accessing functionality not properly constrained by Access Control Lists (ACLs). This means that certain features or areas of the site builder are not correctly restricted, potentially allowing unauthorized access.
Recommendations: For Zita Site Builder versions 1.0.2 and earlier, update to a version that includes the necessary authorization constraints to prevent unauthorized access to functionality. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Missing Authorization

Weakness Enumeration

Related Identifiers

CVE-2024-54369

Affected Products

Zita Site Builder