CVE-2024-50945
Severity CVSS v4.0:
Pending analysis
Type:
CWE-284
Improper Access Control
Publication date:
27/12/2024
Last modified:
18/03/2025
Description
An improper access control vulnerability exists in SimplCommerce at commit 230310c8d7a0408569b292c5a805c459d47a1d8f, allowing users to submit reviews without verifying if they have purchased the product.
Impact
Base Score 3.x
7.50
Severity 3.x
HIGH