Access Control Vulnerability in Newbee Mall by Newbee Ltd
CVE-2020-23448

9.8CRITICAL

Key Information:

Vendor
CVE Published:
26 January 2021

Summary

Newbee Mall is susceptible to an access control vulnerability that enables unauthorized users to escalate privileges. This issue arises from a flaw in the authentication mechanism located in the AdminLoginInterceptor.java, where the security checks can be evaded, granting potential attackers the ability to access sensitive administrative features without proper authorization.

References

CVSS V3.1

Score:
9.8
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.
CVE-2020-23448 : Access Control Vulnerability in Newbee Mall by Newbee Ltd | SecurityVulnerability.io