PT-2024-12206 · Unknown · Awesome Togi Product Category Tree

Friday

·

Published

2024-12-09

·

Updated

2024-12-09

·

CVE-2023-29173

CVSS v3.1

5.3

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
Name of the Vulnerable Software and Affected Versions AWESOME TOGI Product Category Tree versions n/a through 2.5
Description The issue is related to a Missing Authorization vulnerability in the AWESOME TOGI Product Category Tree, which allows exploitation of incorrectly configured access control security levels.
Recommendations For versions n/a through 2.5, update to a version that includes the fix for the Missing Authorization vulnerability. As a temporary workaround, consider restricting access to the Product Category Tree to minimize the risk of exploitation.

Fix

Missing Authorization

Weakness Enumeration

Related Identifiers

CVE-2023-29173

Affected Products

Awesome Togi Product Category Tree