What the vulnerability does
01Description
Missing Authorization vulnerability in Etoile Web Design Order Tracking allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects Order Tracking: from n/a through 3.3.12.
CVSS base score
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N
What the vulnerability does
Missing Authorization vulnerability in Etoile Web Design Order Tracking allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects Order Tracking: from n/a through 3.3.12.
Explanation of Vulnerability in Simple Terms
Order Tracking versions 3.3.12 and earlier lack proper authorization checks, allowing authenticated users to modify data they should not have access to. An attacker with a low-privilege account can alter order information or other protected records. The vulnerability requires login credentials but does not require user interaction beyond normal site usage. Update to a version newer than 3.3.12.
What an attacker can do
Modify order data or other protected records without proper authorization.
Potential impact on your site
Authenticated users can tamper with order information, potentially causing data integrity issues.
Conditions required to exploit
Attacker must have a low-privilege user account on the site.
Key dates
External resources
Related vulnerabilities