DDSN Interactive cm3 Acora CMS
cpe:2.3:a:ddsn:cm3_acora_content_management_system:*:*:*:*:*:*:*
- 10.1.1
A vulnerability has been identified in DDSN Interactive cm3 Acora CMS version 10.1.1, where improper access control allows editor-privileged users to access sensitive information, including system administrator credentials. This is achieved by force browsing the endpoint and exploiting the 'file' parameter. By referencing specific files, such as 'cm3.xml', attackers can bypass access controls, potentially leading to account takeover and privilege escalation.
Exploitation of this vulnerability could result in unauthorized access to sensitive information, such as administrator credentials, allowing for account takeover and privilege escalation.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.