What the vulnerability does
01Description
Missing Authorization vulnerability in MagneticOne Cart2Cart: Magento to WooCommerce Migration.This issue affects Cart2Cart: Magento to WooCommerce Migration: from n/a through 2.0.0.
CVSS base score
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L
What the vulnerability does
Missing Authorization vulnerability in MagneticOne Cart2Cart: Magento to WooCommerce Migration.This issue affects Cart2Cart: Magento to WooCommerce Migration: from n/a through 2.0.0.
Explanation of Vulnerability in Simple Terms
Cart2Cart: Magento to WooCommerce Migration versions up to 2.0.0 lack proper authorization checks on certain operations. A logged-in user with low privileges can modify or delete data they should not have access to. The vulnerability does not expose sensitive information but allows unauthorized changes to site content or functionality.
What an attacker can do
Modify or delete data without proper authorization as a low-privilege logged-in user.
Potential impact on your site
Unauthorized users can alter or remove migration data or settings, potentially corrupting the migration process or site configuration.
Conditions required to exploit
Attacker must have a low-privilege account on the site; no user interaction required.
Key dates
External resources
Related vulnerabilities