IDOR vulnerability in account profile page
Package
Affected versions
2024.04.1
>= 2023.04.1,< 2023.10.9
>= 2022.04.1,< 2022.10.8
>= 2021.04.1,< 2021.10.8
< 2020.10.15
Patched versions
2024.04.2
2023.10.9
2022.10.8
2021.10.8
2020.10.15
Impact
Insecure direct object reference allowing an attacker to disable subscriptions and reviews of another customer