What the vulnerability does
01Description
Missing Authorization vulnerability in Wholesale Team WholesaleX.This issue affects WholesaleX: from n/a through 1.3.1.
CVSS base score
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N
What the vulnerability does
Missing Authorization vulnerability in Wholesale Team WholesaleX.This issue affects WholesaleX: from n/a through 1.3.1.
Explanation of Vulnerability in Simple Terms
WholesaleX versions up to 1.3.1 lack proper authorization checks on certain functions. A logged-in user with low privileges can modify data they should not have access to, such as changing order details or other sensitive records. The vulnerability does not expose confidential information or disrupt service availability. Update to version 2.4.2 or later to resolve this issue.
What an attacker can do
Modify data (orders, records) that should be restricted to higher-privilege users.
Potential impact on your site
Unauthorized users can alter orders, settings, or other protected records without admin approval.
Conditions required to exploit
Attacker must have a low-privilege account on the site and network access to WholesaleX.
Key dates
External resources
Related vulnerabilities