What the vulnerability does
01Description
Missing Authorization vulnerability in Peach Payments Peach Payments Gateway.This issue affects Peach Payments Gateway: from n/a through 3.1.9.
CVSS base score
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L
What the vulnerability does
Missing Authorization vulnerability in Peach Payments Peach Payments Gateway.This issue affects Peach Payments Gateway: from n/a through 3.1.9.
Explanation of Vulnerability in Simple Terms
Peach Payments Gateway versions up to 3.1.9 lack proper authorization checks, allowing authenticated users to modify or disable functionality they should not have access to. An attacker with low-level account privileges can alter system settings or disable features without proper permission validation. This affects the integrity and availability of payment processing operations.
What an attacker can do
Modify or disable payment gateway features without proper authorization.
Potential impact on your site
Unauthorized users can alter payment settings or disable critical gateway functions, disrupting transactions.
Conditions required to exploit
Attacker must have a low-privilege authenticated account on the system.
Key dates
External resources
Related vulnerabilities