PT-2024-12572 · Itb Gmbh · Itb-Gmbh Tradepro

Published

2024-04-04

·

Updated

2025-04-24

·

CVE-2023-36643

CVSS v3.1

7.5

High

VectorAC:L/AV:N/A:N/C:H/I:N/PR:N/S:U/UI:N
Name of the Vulnerable Software and Affected Versions ITB-GmbH TradePro version 9.5
Description The issue allows remote attackers to bypass access controls and receive all orders from the online shop. This is achieved via the oordershow component in the customer function.
Recommendations For ITB-GmbH TradePro version 9.5, consider restricting access to the oordershow component in the customer function until a patch is available.

Exploit

Fix

Improper Access Control

Weakness Enumeration

Related Identifiers

CVE-2023-36643

Affected Products

Itb-Gmbh Tradepro