What the vulnerability does
01Description
Missing Authorization vulnerability in Welcart Inc. Welcart e-Commerce.This issue affects Welcart e-Commerce: from n/a through 2.9.14.
CVSS base score
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L
What the vulnerability does
Missing Authorization vulnerability in Welcart Inc. Welcart e-Commerce.This issue affects Welcart e-Commerce: from n/a through 2.9.14.
Explanation of Vulnerability in Simple Terms
Welcart e-Commerce versions up to 2.9.14 lack proper authorization checks, allowing authenticated users to modify or delete data they should not have access to. An attacker with a low-privilege account can alter product information, orders, or other sensitive records without restriction. This affects the integrity and availability of the e-commerce platform's core data.
What an attacker can do
Modify or delete orders, products, and other data without proper permission checks.
Potential impact on your site
Customers or staff with basic accounts can corrupt product listings, orders, and business records.
Conditions required to exploit
Attacker must have a valid low-privilege user account on the site.
Key dates
External resources
Related vulnerabilities