What the vulnerability does
01Description
Missing Authorization vulnerability in Codection Import and export users and customers.This issue affects Import and export users and customers: from n/a through 1.24.6.
CVSS base score
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
What the vulnerability does
Missing Authorization vulnerability in Codection Import and export users and customers.This issue affects Import and export users and customers: from n/a through 1.24.6.
Explanation of Vulnerability in Simple Terms
The Import and export users and customers plugin for Codection versions up to 1.24.6 lacks proper authorization checks on certain functions. An attacker without authentication can modify user or customer data through direct requests. The vulnerability does not expose sensitive information but allows unauthorized changes to records in the system.
What an attacker can do
Modify user or customer data without logging in.
Potential impact on your site
Attackers can alter user and customer records, potentially disrupting data integrity and user accounts.
Conditions required to exploit
Network access to the site; no authentication or user interaction required.
Key dates
External resources
Related vulnerabilities