#VU25602 Permissions, Privileges, and Access Controls in Pricing Table by Supsystic - CVE-2020-9392
Published: February 26, 2020
Pricing Table by Supsystic
supsystic.com
Description
The vulnerability allows a remote attacker to escalate privileges on the system.
The vulnerability exists due to insecure permissions on several AJAX actions. A remote attacker can obtain sensitive information regarding any given pricing table while creating and importing new pricing tables or altering already existing ones.