PT-2024-27301 · Unknown · Wishlist Member

Dave Jong

·

Published

2024-11-01

·

Updated

2024-11-01

·

CVE-2024-37106

CVSS v3.1

8.2

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:H
Name of the Vulnerable Software and Affected Versions WishList Member X versions 3.26.6 and earlier
Description The issue is related to a Missing Authorization vulnerability, allowing the exploitation of incorrectly configured access control security levels.
Recommendations For versions 3.26.6 and earlier, update to a version later than 3.26.6 to resolve the issue. As a temporary workaround, consider restricting access to sensitive areas of WishList Member X to minimize the risk of exploitation.

Fix

Missing Authorization

Weakness Enumeration

Related Identifiers

CVE-2024-37106

Affected Products

Wishlist Member