What the vulnerability does
01Description
Missing Authorization vulnerability in FunnelKit FunnelKit Checkout.This issue affects FunnelKit Checkout: from n/a through 3.10.3.
CVSS base score
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
What the vulnerability does
Missing Authorization vulnerability in FunnelKit FunnelKit Checkout.This issue affects FunnelKit Checkout: from n/a through 3.10.3.
Explanation of Vulnerability in Simple Terms
FunnelKit Checkout versions up to 3.10.3 lack proper authorization checks, allowing unauthenticated attackers to disrupt the service. An attacker can send requests over the network without authentication to trigger a denial-of-service condition. No user interaction is required. Site administrators should update to a version newer than 3.10.3.
What an attacker can do
Make the site unavailable or unresponsive by sending network requests without logging in.
Potential impact on your site
Checkout functionality may become unavailable to legitimate customers during an attack.
Conditions required to exploit
Network access only; no authentication or user interaction required.
Key dates
External resources
Related vulnerabilities