Vulnerabilities > CVE-2020-23449 - Authorization Bypass Through User-Controlled Key vulnerability in Newbee-Mall Project Newbee-Mall

047910
CVSS 7.5 - HIGH
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
NONE
Integrity impact
HIGH
Availability impact
NONE
network
low complexity
newbee-mall-project
CWE-639

Summary

newbee-mall all versions are affected by incorrect access control to remotely gain privileges through NewBeeMallIndexConfigServiceImpl.java. Unauthorized changes can be made to any user information through the userID.

Vulnerable Configurations

Part Description Count
Application
Newbee-Mall_Project
1