Vulnerability Description
Incorrect Access Control in ITB-GmbH TradePro v9.5, allows remote attackers to receive all order confirmations from the online shop via the printmail plugin.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Itb-Pim | Tradepro | 9.5 |
Related Weaknesses (CWE)
References
- https://github.com/caffeinated-labs/CVE-2023-36644ExploitThird Party Advisory
- https://github.com/caffeinated-labs/CVE-2023-36644ExploitThird Party Advisory
FAQ
What is CVE-2023-36644?
CVE-2023-36644 is a vulnerability with a CVSS score of 7.5 (HIGH). Incorrect Access Control in ITB-GmbH TradePro v9.5, allows remote attackers to receive all order confirmations from the online shop via the printmail plugin.
How severe is CVE-2023-36644?
CVE-2023-36644 has been rated HIGH with a CVSS base score of 7.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2023-36644?
Check the references section above for vendor advisories and patch information. Affected products include: Itb-Pim Tradepro.