Incorrect Access Control in Shopxo by Gongfuxiang
CVE-2020-19778

9.8CRITICAL

Key Information:

Vendor

Shopxo

Status
Vendor
CVE Published:
14 April 2021

What is CVE-2020-19778?

A vulnerability in the Shopxo application allows remote attackers to exploit improper access control by manipulating the 'user_id' parameter in an HTML request. This can lead to unauthorized privilege escalation, enabling malicious actors to gain elevated access to sensitive functions and data within the application. It is critical for users of Shopxo to apply necessary security measures and update to secure versions.

References

CVSS V3.1

Score:
9.8
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.
CVE-2020-19778 : Incorrect Access Control in Shopxo by Gongfuxiang