#VU26057 Improper access control in Fruitful
Published: March 13, 2020
Fruitful
Fruitful Code
Description
The vulnerability allows a remote attacker to gain unauthorized access to otherwise restricted functionality.
The vulnerability exists due to improper access restrictions in several AJAX actions. A remote authenticated attacker can bypass implemented security restrictions and delete the theme options, adds one or more input fields while editing the theme and throw a fatal error.
Vulnerable AJAX function:
- fruitful_reset_btn
- fruitful_add_new_slide_action
- run_import_dummy_data