What the vulnerability does
01Description
Missing Authorization vulnerability in TechnoVama Quotes for WooCommerce.This issue affects Quotes for WooCommerce: from n/a through 2.0.1.
CVSS base score
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N
What the vulnerability does
Missing Authorization vulnerability in TechnoVama Quotes for WooCommerce.This issue affects Quotes for WooCommerce: from n/a through 2.0.1.
Explanation of Vulnerability in Simple Terms
Quotes for WooCommerce versions up to 2.0.1 lack proper authorization checks, allowing authenticated users to modify quote data they should not have access to. An attacker with a low-privilege account can alter quotes belonging to other users or administrators. The vulnerability requires an active user account but no special interaction from victims.
What an attacker can do
Modify or tamper with quotes belonging to other users or administrators.
Potential impact on your site
Customer and admin quotes can be altered by unauthorized users, risking data integrity and business process disruption.
Conditions required to exploit
Attacker must have a valid WooCommerce user account with low-level privileges.
Key dates
External resources
Related vulnerabilities