What the vulnerability does
01Description
Missing Authorization vulnerability in FunnelKit FunnelKit Checkout.This issue affects FunnelKit Checkout: from n/a through 3.10.3.
CVSS base score
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N
What the vulnerability does
Missing Authorization vulnerability in FunnelKit FunnelKit Checkout.This issue affects FunnelKit Checkout: from n/a through 3.10.3.
Explanation of Vulnerability in Simple Terms
FunnelKit Checkout versions up to 3.10.3 lack proper authorization checks, allowing authenticated users to modify data they should not have access to. An attacker with a low-privilege account can alter information through the application without proper permission validation. The vulnerability affects data integrity but does not expose sensitive information or disrupt service availability.
What an attacker can do
Modify data in the checkout system that should be restricted to higher-privilege users.
Potential impact on your site
Checkout data integrity may be compromised by low-privilege users making unauthorized changes.
Conditions required to exploit
Attacker must have a low-privilege account on the site; no user interaction required.
Key dates
External resources
Related vulnerabilities