What the vulnerability does
01Description
Missing Authorization vulnerability in FunnelKit FunnelKit Checkout.This issue affects FunnelKit Checkout: from n/a through 3.10.3.
CVSS base score
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L
What the vulnerability does
Missing Authorization vulnerability in FunnelKit FunnelKit Checkout.This issue affects FunnelKit Checkout: from n/a through 3.10.3.
Explanation of Vulnerability in Simple Terms
FunnelKit Checkout versions up to 3.10.3 lack proper authorization checks, allowing authenticated users to modify or disable checkout functionality they should not have access to. An attacker with low-level site access can alter checkout settings or availability without proper permission validation. This affects data integrity and site availability for e-commerce operations.
What an attacker can do
Modify or disable checkout settings and functionality without proper authorization.
Potential impact on your site
Checkout functionality may be altered or disabled by unauthorized users, disrupting sales and customer transactions.
Conditions required to exploit
Attacker must have a low-privilege authenticated account on the site.
Key dates
External resources
Related vulnerabilities