Permissions, Privileges, and Access Controls in Pricing Table by Supsystic - CVE-2020-9392

 

Permissions, Privileges, and Access Controls in Pricing Table by Supsystic - CVE-2020-9392

Published: February 26, 2020


Vulnerability identifier: #VU25602
CSH Severity: Medium
CVSS v4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N]
CVE-ID: CVE-2020-9392
CWE-ID: CWE-264
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to escalate privileges on the system.

The vulnerability exists due to insecure permissions on several AJAX actions. A remote attacker can obtain sensitive information regarding any given pricing table while creating and importing new pricing tables or altering already existing ones.


Affected software

Pricing Table by Supsystic

How to mitigate CVE-2020-9392

Install updates from vendor's website.

Pricing Table by Supsystic - update to 1.8.2

External References

Related Security Bulletins