Incorrect Authorization vulnerability in Drupal Commerce View Receipt allows Forceful Browsing.This issue affects Commerce View Receipt: from 0.0.0 before 1.0.3.

Subscriptions

Vendors Products
Commerce View Receipt Project Subscribe
Commerce View Receipt Subscribe

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2024-51471 Incorrect Authorization vulnerability in Drupal Commerce View Receipt allows Forceful Browsing.This issue affects Commerce View Receipt: from 0.0.0 before 1.0.3.
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

References
History

Wed, 04 Jun 2025 16:00:00 +0000

Type Values Removed Values Added
First Time appeared Commerce View Receipt Project
Commerce View Receipt Project commerce View Receipt
CPEs cpe:2.3:a:commerce_view_receipt_project:commerce_view_receipt:*:*:*:*:*:drupal:*:*
Vendors & Products Commerce View Receipt Project
Commerce View Receipt Project commerce View Receipt

Fri, 10 Jan 2025 17:15:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 5.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N'}

ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 09 Jan 2025 19:15:00 +0000

Type Values Removed Values Added
Description Incorrect Authorization vulnerability in Drupal Commerce View Receipt allows Forceful Browsing.This issue affects Commerce View Receipt: from 0.0.0 before 1.0.3.
Title Commerce View Receipt - Moderately critical - Access bypass - SA-CONTRIB-2024-021
Weaknesses CWE-863
References

cve-icon MITRE

Status: PUBLISHED

Assigner: drupal

Published:

Updated: 2025-01-10T16:50:24.727Z

Reserved: 2025-01-09T18:27:19.257Z

Link: CVE-2024-13257

cve-icon Vulnrichment

Updated: 2025-01-10T16:50:18.974Z

cve-icon NVD

Status : Analyzed

Published: 2025-01-09T19:15:19.773

Modified: 2025-06-04T15:09:44.690

Link: CVE-2024-13257

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses