Improper access control in Advanced AJAX Product Filters - #VU21198
Published: September 18, 2019
Vulnerability identifier: #VU21198
CSH Severity: High
CVSS v4: 9.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: N/A
CWE-ID: CWE-284
Exploitation vector: Remote access
Exploit availability:
The vulnerability is being exploited in the wild
Vulnerability details
The vulnerability allows a remote attacker to compromise vulnerable website.
The vulnerability exists due to improper access restrictions. A remote attacker can bypass implemented security restrictions and gain unauthorized access to the website.
Note, this vulnerability is being actively exploited in the wild.
Affected software
Advanced AJAX Product Filters
Remediation
Install updates from vendor's website.
Advanced AJAX Product Filters - update to 1.3.7