Incorrect Access Control in Shopxo v1.4.0 and v1.5.0 allows remote attackers to gain privileges in /index.php by manipulating the parameter user_id in the HTML request.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Shopxo | Shopxo | 1.4.0 (including) | 1.4.0 (including) |
Shopxo | Shopxo | 1.5.0 (including) | 1.5.0 (including) |