Description
In Shopizer versions 2.0 to 2.17.0 a regular admin can permanently delete a superadmin (although this cannot happen according to the documentation) via Insecure Direct Object Reference (IDOR) vulnerability.
No analysis available yet.
Remediation
Vendor Solution
Upgrade version to 3.0.0 or higher
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2022-28170 | In Shopizer versions 2.0 to 2.17.0 a regular admin can permanently delete a superadmin (although this cannot happen according to the documentation) via Insecure Direct Object Reference (IDOR) vulnerability. |
References
History
No history.
Status: PUBLISHED
Assigner: Mend
Published:
Updated: 2024-09-17T02:05:46.247Z
Reserved: 2022-01-10T00:00:00.000Z
Link: CVE-2022-23061
No data.
Status : Modified
Published: 2022-05-01T13:15:07.757
Modified: 2024-11-21T06:47:54.587
Link: CVE-2022-23061
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD