Authorization Flaw in UkrSolution Barcode Scanner with Inventory & Order Manager from UkrSolution
CVE-2024-32589

7.1HIGH

What is CVE-2024-32589?

The UkrSolution Barcode Scanner with Inventory & Order Manager suffers from a missing authorization vulnerability that could allow an unauthenticated user to exploit the system. This issue affects versions up to 1.5.3 and presents a significant risk, enabling unauthorized access to features intended solely for administrators. It is critical for users of this product to assess their systems and take appropriate measures, such as applying security patches or updates, to protect against potential exploits.

Affected Version(s)

Barcode Scanner with Inventory & Order Manager <= 1.5.3

References

CVSS V3.1

Score:
7.1
Severity:
HIGH
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Maksim Kosenko (Patchstack Bug Bounty program)
.