Permissions, Privileges, and Access Controls in MStore API - #VU25988

 

Permissions, Privileges, and Access Controls in MStore API - #VU25988

Published: March 11, 2020


Vulnerability identifier: #VU25988
CSH Severity: High
CVSS v4: 9.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: N/A
CWE-ID: CWE-264
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to escalate privileges on the system.

The vulnerability exists due to improper permission checks in the "mstore-api/controllers/FlutterUser.php" script in "register" and "update_user_profile" functions. A remote attacker can create an administrator account or modify any account on the blog such as the administrator account’s password or email address.


Affected software

MStore API

Remediation

Install updates from vendor's website.

MStore API - update to 2.1.6

External References

Related Security Bulletins