Home
CRITICAL: 9.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:NDefault status
unaffected
7.4.0 (semver)
affected
18.13.0 (semver) before 18.13.3
affected
9.0.0 (semver) before 9.0.4
affected
Description
Insufficient ownership check in `clientarea.php` allows an authenticated client area user to submit requests using another user’s `addonId` without any ownership validation leading to unauthorized access to the victim's account.
Problem types
CWE-639 Insecure Direct Object Reference (IDOR)
Product status
7.4.0 (semver)
18.13.0 (semver) before 18.13.3
9.0.0 (semver) before 9.0.4
References
help.whmcs.com/m/125386/l/2073908-cve-2026-29204