An improper access control vulnerability exists in SimplCommerce at commit 230310c8d7a0408569b292c5a805c459d47a1d8f, allowing users to submit reviews without verifying if they have purchased the product.
References
Configurations
No configuration.
History
18 Mar 2025, 19:15
Type | Values Removed | Values Added |
---|---|---|
CWE | CWE-284 | |
CVSS |
v2 : v3 : |
v2 : unknown
v3 : 7.5 |
18 Feb 2025, 22:15
Type | Values Removed | Values Added |
---|---|---|
Summary |
|
|
CWE | ||
CVSS |
v2 : v3 : |
v2 : unknown
v3 : unknown |
28 Dec 2024, 19:15
Type | Values Removed | Values Added |
---|---|---|
CVSS |
v2 : v3 : |
v2 : unknown
v3 : 7.5 |
CWE | CWE-863 |
27 Dec 2024, 19:15
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2024-12-27 19:15
Updated : 2025-03-18 19:15
NVD link : CVE-2024-50945
Mitre link : CVE-2024-50945
CVE.ORG link : CVE-2024-50945
JSON object : View
Products Affected
No product.
CWE
CWE-284
Improper Access Control