What the vulnerability does
01Description
Missing Authorization vulnerability in paypalmuse PayPal Marketing Solutions paypal-promotions-and-insights allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects PayPal Marketing Solutions: from n/a through <= 1.2.
Explanation of Vulnerability in Simple Terms
02Summary
PayPal Marketing Solutions versions 1.2 and earlier lack proper authorization checks, allowing authenticated users with low privileges to modify data they should not have access to. An attacker with a basic user account can alter settings or records without proper permission validation. The vulnerability requires an existing account but does not require user interaction from a victim.
What an attacker can do
03Attacker Capabilities
Modify data or settings in PayPal Marketing Solutions without proper authorization.
Potential impact on your site
04Site Impact
Users with basic accounts can alter configuration or data they should not be able to change, risking data integrity.
Conditions required to exploit
05Prerequisites
Attacker must have a low-privilege user account on the affected system.
Key dates
06Disclosure timeline
January 16, 2025
CVE published
May 11, 2026
Record updated