What the vulnerability does
01Description
Missing Authorization vulnerability in Kings Plugins B2BKing allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects B2BKing: from n/a before 5.2.10.
CVSS base score
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:H/A:N
What the vulnerability does
Missing Authorization vulnerability in Kings Plugins B2BKing allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects B2BKing: from n/a before 5.2.10.
Explanation of Vulnerability in Simple Terms
B2BKing versions before 5.2.10 lack proper authorization checks, allowing high-privilege users to modify data they should not access. The vulnerability requires an authenticated admin or manager account to exploit. No confidentiality impact occurs, but attackers can alter site content or settings. Update to version 5.2.10 or later to resolve this issue.
What an attacker can do
Modify or alter data and settings beyond their authorized scope.
Potential impact on your site
Privileged users could tamper with B2BKing configuration, business rules, or customer data without proper restrictions.
Conditions required to exploit
Attacker must have admin or manager-level access to the B2BKing plugin.
Key dates
External resources
Related vulnerabilities