Improper access control in Advanced AJAX Product Filters - #VU21198

 

Improper access control in Advanced AJAX Product Filters - #VU21198

Published: September 18, 2019


Vulnerability identifier: #VU21198
CSH Severity: High
CVSS v4.0: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:A/U:Amber
CVE-ID: N/A
CWE-ID: CWE-284
Exploitation vector: Remote access
Exploit availability: The vulnerability is being exploited in the wild
Vendor: BeRocket
Affected software:
Advanced AJAX Product Filters

Detailed vulnerability description

The vulnerability allows a remote attacker to compromise vulnerable website.

The vulnerability exists due to improper access restrictions. A remote attacker can bypass implemented security restrictions and gain unauthorized access to the website.

Note, this vulnerability is being actively exploited in the wild.


Remediation

Install updates from vendor's website.

Sources