Intel

AIKIDO-2025-10203

spryker-shop/company-page is vulnerable to Broken Access Control

Broken Access Control Pre-CVE
Found by Aikido Intel before public disclosure or CVE publication.

92

Critical Risk

This Affects:

PHPspryker-shop/company-page
0.0.1 - 2.35.0
Fixed in 2.35.1

TL;DR

Affected versions of this package are vulnerable to broken access control in the executeCreateAction and executeUpdateAction methods. Insufficient validation in these actions allows users to create or update accounts outside their own company. An attacker can exploit this by forging requests to manipulate users in other companies, potentially leading to privilege escalation or unauthorized access.

Who does this affect?

You are affected if you are using a version that falls within the vulnerable range.

Background info

spryker-shop/company-page is vulnerable to Broken Access Control in versions 0.0.1 - 2.35.0.

How to fix this

Upgrade the spryker-shop/company-page library to the patch version.