CVE-2022-23061
01.05.2022, 13:15
In Shopizer versions 2.0 to 2.17.0 a regular admin can permanently delete a superadmin (although this cannot happen according to the documentation) via Insecure Direct Object Reference (IDOR) vulnerability.Enginsight
Vendor | Product | Version |
---|---|---|
shopizer | shopizer | 2.0 ≤ 𝑥 ≤ 2.17.0 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration
References