spryker-shop/company-page is vulnerable to Broken Access Control
92
Critical Risk
Affected versions of this package are vulnerable to broken access control in the executeCreateAction and executeUpdateAction methods. Insufficient validation in these actions allows users to create or update accounts outside their own company. An attacker can exploit this by forging requests to manipulate users in other companies, potentially leading to privilege escalation or unauthorized access.
You are affected if you are using a version that falls within the vulnerable range.
spryker-shop/company-page is vulnerable to Broken Access Control in versions 0.0.1 - 2.35.0.
Upgrade the spryker-shop/company-page library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

SOC 2Compliant
ISO 27001Compliant