What the vulnerability does
01Description
Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Store Locator Plus.This issue affects Store Locator Plus: from n/a through 2311.17.01.
CVSS base score
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
What the vulnerability does
Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Store Locator Plus.This issue affects Store Locator Plus: from n/a through 2311.17.01.
Explanation of Vulnerability in Simple Terms
Store Locator Plus versions up to 2311.17.01 expose sensitive information that can be accessed over the network without authentication. An attacker can retrieve this data directly without needing to log in or interact with a user. The vulnerability affects the application's confidentiality but does not allow modification or disruption of service.
What an attacker can do
Read sensitive information from the application without logging in.
Potential impact on your site
Sensitive data may be exposed to unauthorized parties if the site runs an affected version.
Conditions required to exploit
Network access to the affected Store Locator Plus installation; no authentication required.
Key dates
External resources
Related vulnerabilities