First published: Thu May 04 2023(Updated: )
Insecure permissions in the updateUserInfo function of newbee-mall before commit 1f2c2dfy allows attackers to obtain user account information.
Credit: cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
newbee-mall | <2022-10-27 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2023-30216 is considered a medium severity vulnerability due to insecure permissions in user information updates.
To fix CVE-2023-30216, update to newbee-mall version 2022-10-27 or later which addresses the insecure permissions issue.
CVE-2023-30216 allows attackers to obtain sensitive user account information due to improper permissions in the updateUserInfo function.
Users of newbee-mall versions prior to 2022-10-27 are affected by CVE-2023-30216.
If unable to update, implement strict access controls and monitor user account activity to mitigate the impact of CVE-2023-30216.