Incorrect Access Control in Shopxo v1.4.0 and v1.5.0 allows remote attackers to gain privileges in /index.php by manipulating the parameter user_id in the HTML request.
| Name | Vendor | Start Version | End Version |
|---|---|---|---|
| Shopxo | Shopxo | 1.4.0 (including) | 1.4.0 (including) |
| Shopxo | Shopxo | 1.5.0 (including) | 1.5.0 (including) |