Home

Description

Missing Authorization vulnerability in wooproductimporter Sharkdropship dropshipping for Aliexpress, eBay, Amazon, etsy allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Sharkdropship dropshipping for Aliexpress, eBay, Amazon, etsy: from n/a through 2.1.1.

PUBLISHED Reserved 2023-11-30 | Published 2024-12-09 | Updated 2024-12-10 | Assigner Patchstack




MEDIUM: 6.5CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L

Problem types

CWE-862 Missing Authorization

Product status

Default status
unaffected

Any version
affected

Credits

Nguyen Xuan Chien (Patchstack Alliance) finder

References

patchstack.com/...ken-access-control-vulnerability?_s_id=cve vdb-entry

cve.org (CVE-2023-49848)

nvd.nist.gov (CVE-2023-49848)

Download JSON