What the vulnerability does
01Description
Unauthenticated Broken Authentication in Cartify <= 1.3.0.1 versions.
CVSS base score
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
What the vulnerability does
Unauthenticated Broken Authentication in Cartify <= 1.3.0.1 versions.
Explanation of Vulnerability in Simple Terms
Cartify versions up to 1.3.0.1 contain an authentication bypass vulnerability that allows attackers to access the application without valid credentials. The flaw exists in an alternate authentication path or channel, enabling complete compromise of confidentiality, integrity, and availability. No authentication or user interaction is required to exploit this issue.
What an attacker can do
Bypass authentication and gain full access to the application without valid credentials.
Potential impact on your site
Attackers can read, modify, or delete all data and functionality without logging in.
Conditions required to exploit
Network access to the application. No authentication or user interaction required.
Key dates
External resources
Related vulnerabilities