spryker-shop/company-page is vulnerable to Broken Access Control
92
Critical Risk
Affected versions of this package are vulnerable to broken access control in the executeCreateAction and executeUpdateAction methods. Insufficient validation in these actions allows users to create or update accounts outside their own company. An attacker can exploit this by forging requests to manipulate users in other companies, potentially leading to privilege escalation or unauthorized access.
You are affected if you are using a version that falls within the vulnerable range.
spryker-shop/company-page is vulnerable to Broken Access Control in versions 0.0.1 - 2.35.0.
Upgrade the spryker-shop/company-page library to the patch version.
Secure your code, cloud, and runtime environments in one central system. Find and fix vulnerabilities automatically.
No credit card required | Scan results in 32secs.
SOC 2Compliant
ISO 27001Compliant