Annex Cloud Loyalty Experience Platform <2021.1.0.1 allows any authenticated attacker to modify loyalty campaigns and settings, such as fraud prevention, coupon groups, email templates, or referrals.
The product specifies permissions for a security-critical resource in a way that allows that resource to be read or modified by unintended actors.
Link | Tags |
---|---|
https://github.com/Accenture/AARO-Bugs/blob/master/AARO-CVE-List.md | third party advisory |
https://www.annexcloud.com/ | product vendor advisory |