Home

Description

Incorrect Access Control in ITB-GmbH TradePro v9.5, allows remote attackers to receive all orders from the online shop via oordershow component in customer function.

PUBLISHED Reserved 2023-06-25 | Published 2024-04-04 | Updated 2024-08-02 | Assigner mitre




HIGH: 7.5CVSS:3.1/AC:L/AV:N/A:N/C:H/I:N/PR:N/S:U/UI:N

References

github.com/caffeinated-labs/CVE-2023-36643

github.com/caffeinated-labs/CVE-2023-36643

cve.org (CVE-2023-36643)

nvd.nist.gov (CVE-2023-36643)

Download JSON