Vulnerabilities > CVE-2020-23449 - Incorrect Authorization vulnerability in Newbee-Mall Project Newbee-Mall

047910
CVSS 5.0 - MEDIUM
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
NONE
Integrity impact
PARTIAL
Availability impact
NONE
network
low complexity
newbee-mall-project
CWE-863

Summary

newbee-mall all versions are affected by incorrect access control to remotely gain privileges through NewBeeMallIndexConfigServiceImpl.java. Unauthorized changes can be made to any user information through the userID.

Vulnerable Configurations

Part Description Count
Application
Newbee-Mall_Project
1

Common Weakness Enumeration (CWE)