Impact
Missing authentication protects a critical function in the FTC E-Commerce Management Panel, leading to uncontrolled access by unauthenticated users. The vulnerability exploits CWE-306 and can enable users to modify product listings, manage orders, or alter configurations without permission.
Affected Systems
FTC Software IT Services provides the FTC E-Commerce Management Panel. Version 1.0.1 and earlier are affected; any release before 1.0.2 is vulnerable.
Risk and Exploitability
The CVSS score of 8.2 indicates high severity. The EPSS score is 0.00255, reflecting a very low exploitation probability, and the vulnerability is not listed in the CISA KEV catalog. Attackers can most likely exploit the weakness remotely by accessing the web interface of the panel, bypassing authentication controls.
OpenCVE Enrichment