What the vulnerability does
01Description
Missing Authorization vulnerability in ZAYTECH Smart Online Order for Clover clover-online-orders.This issue affects Smart Online Order for Clover: from n/a through <= 1.5.6.
CVSS base score
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N
What the vulnerability does
Missing Authorization vulnerability in ZAYTECH Smart Online Order for Clover clover-online-orders.This issue affects Smart Online Order for Clover: from n/a through <= 1.5.6.
Explanation of Vulnerability in Simple Terms
Smart Online Order for Clover versions up to 1.5.6 lack proper authorization checks, allowing authenticated users to modify data they should not have access to. An attacker with a low-privilege account can alter information through the application's API or interface without additional restrictions. This affects the integrity of order and customer data within the Clover payment system integration.
What an attacker can do
Modify order or customer data without proper authorization.
Potential impact on your site
Customer orders and data may be altered by unauthorized users with basic account access.
Conditions required to exploit
Attacker must have a valid low-privilege account on the Clover system.
Key dates
External resources
Related vulnerabilities