Vulnerabilities > CVE-2024-37930 - Missing Authorization vulnerability in Theme-Sphere Smartmag

047910
CVSS 7.5 - HIGH
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
HIGH
Integrity impact
NONE
Availability impact
NONE
network
low complexity
theme-sphere
CWE-862

Summary

Exposure of Sensitive Information to an Unauthorized Actor, Missing Authorization vulnerability in ThemeSphere SmartMag allows Excavation, Accessing Functionality Not Properly Constrained by ACLs.This issue affects SmartMag: from n/a through 9.3.0.

Vulnerable Configurations

Part Description Count
Application
Theme-Sphere
1

Common Weakness Enumeration (CWE)