CVE-2024-50945
CVSS 3.1 Score 7.5 of 10 (high)
Details
Published Dec 27, 2024
Updated: Mar 18, 2025
CWE ID 284
Summary
CVE-2024-50945 is a newly identified access control vulnerability affecting SimplCommerce. This issue, which can be traced back to commit 230310c8d7a0408569b292c5a805c459d47a1d8f, enables unauthenticated users to submit product reviews, bypassing the requirement to verify if they have previously purchased the item. This oversight poses a risk of malicious reviews being posted and could potentially harm the reputation of affected e-commerce sites. Retailers using SimplCommerce are urged to update to a patched version as soon as possible to mitigate the risk.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.