What the vulnerability does
01Description
Missing Authorization vulnerability in Easy Digital Downloads allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Easy Digital Downloads: from n/a through 3.2.12.
CVSS base score
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
What the vulnerability does
Missing Authorization vulnerability in Easy Digital Downloads allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Easy Digital Downloads: from n/a through 3.2.12.
Explanation of Vulnerability in Simple Terms
Easy Digital Downloads versions up to 3.2.12 fail to properly check user permissions before allowing access to sensitive data. A logged-in user with low privileges can read information they should not have access to, such as other users' purchase history or payment details. The vulnerability requires an active user account but no special interaction from the victim.
What an attacker can do
Read sensitive data belonging to other users, such as purchase history or payment information.
Potential impact on your site
Customer data and purchase records may be exposed to other registered users on your site.
Conditions required to exploit
Attacker must have a low-privilege user account on the site; no victim interaction required.
Key dates
External resources
Related vulnerabilities