#VU21198 Improper access control in Advanced AJAX Product Filters

 

#VU21198 Improper access control in Advanced AJAX Product Filters

Published: September 18, 2019


Vulnerability identifier: #VU21198
Vulnerability risk: High
CVSSv4.0: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:A/U:Amber
CVE-ID: N/A
CWE-ID: CWE-284
Exploitation vector: Remote access
Exploit availability: The vulnerability is being exploited in the wild
Vulnerable software:
Advanced AJAX Product Filters
Software vendor:
BeRocket

Description

The vulnerability allows a remote attacker to compromise vulnerable website.

The vulnerability exists due to improper access restrictions. A remote attacker can bypass implemented security restrictions and gain unauthorized access to the website.

Note, this vulnerability is being actively exploited in the wild.


Remediation

Install updates from vendor's website.

External links