#VU26363 Improper access control in Data Tables Generator by Supsystic
Published: March 25, 2020
Data Tables Generator by Supsystic
supsystic.com
Description
The vulnerability allows a remote attacker to gain unauthorized access to otherwise restricted functionality.
The vulnerability exists due to improper access restrictions in several AJAX actions. A remote authenticated attacker can bypass implemented security restrictions, execute the actions and make malicious changes to any given data table, or create a new data table.
This vulnerability affects the following endpoints:
- getListForTbl
- updateRows
- updateMeta
- saveSettings
- remove
- create
- render
- getSettings
- getMeta
- getCountRows
- getRows
- clone
- rename