PT-2026-81241 · Unknown · Club Directory
CVSS v4.0
8.8
High
| Vector | AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:H/VA:N/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
Club Directory (affected versions not specified)
Description
Broken access control exists in the frontend edit, update, and activate actions. The extension resolves the targeted club record from a user-supplied request argument but fails to perform an ownership check. Consequently, an unauthenticated visitor who knows the UID of a club record can send a direct request to the update or activate action to overwrite the record or publish one that is awaiting approval without owning it.
Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Missing Authorization
IDOR
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Club Directory