Home
MEDIUM: 5.4 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:NDefault status
unaffected
Any version
affected
Description
Missing Authorization vulnerability in BeRocket Advanced AJAX Product Filters allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Advanced AJAX Product Filters: from n/a through 1.6.3.3.
Problem types
Product status
Any version
Credits
István Márton | Patchstack Bug Bounty Program
References
patchstack.com/...6-3-3-broken-access-control-csrf?_s_id=cve