Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:31394
HistoryJul 28, 2021 - 4:55 a.m.

Insecure Access Control

2021-07-2804:55:23
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
7

0.001 Low

EPSS

Percentile

22.7%

directmailteam/direct-mail uses insecure access controls. The extension fails to check if an authenticated backend user has access to newsletter subscriber tables (e.g. tt_address, fe_users) when using the CSV export function of the extension.

0.001 Low

EPSS

Percentile

22.7%

Related for VERACODE:31394