PT-2024-11977 · Shopfiles · Ebook Store

Yuyudhn

·

Published

2024-12-09

·

Updated

2025-11-07

·

CVE-2023-22701

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Shopfiles Ltd Ebook Store versions n/a through 5.775
Description The issue is related to a Missing Authorization vulnerability, which allows the exploitation of incorrectly configured access control security levels. This vulnerability affects the Ebook Store, enabling potential unauthorized access due to missing authorization checks.
Recommendations For versions n/a through 5.775, consider restricting access to sensitive areas of the Ebook Store to minimize the risk of exploitation until a proper fix is available. As a temporary workaround, review and correct the configuration of access control security levels to ensure proper authorization is enforced. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Missing Authorization

Weakness Enumeration

Related Identifiers

CVE-2023-22701

Affected Products

Ebook Store