← Back

Annexcloud

annexcloud

3 CVEs • 1 product

Products (1)

Click to collapse
Toggle

CVEs (3)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Annexcloud
1Loyalty Experience Platform
Nov 21, 2024
Jun 10, 2021
N/A· v4
8.8 HIGH· v3
9.0 HIGH· v2
Annex Cloud Loyalty Experience Platform <2021.1.0.1 allows any authenticated attacker to escalate privileges to superadministrator. It was fixed in v2021.1.0.2.
1Annexcloud
1Loyalty Experience Platform
Nov 21, 2024
Jun 10, 2021
N/A· v4
4.3 MEDIUM· v3
4.0 MEDIUM· v2
An Insecure Direct Object Reference (IDOR) vulnerability in Annex Cloud Loyalty Experience Platform <2021.1.0.1 allows any authenticated attacker to modify any existing user, including users assigned to different environ...Show more
An Insecure Direct Object Reference (IDOR) vulnerability in Annex Cloud Loyalty Experience Platform <2021.1.0.1 allows any authenticated attacker to modify any existing user, including users assigned to different environments and clients. It was fixed in v2021.1.0.2.Show less
1Annexcloud
1Loyalty Experience Platform
Nov 21, 2024
Jun 10, 2021
N/A· v4
4.3 MEDIUM· v3
4.0 MEDIUM· v2
Annex Cloud Loyalty Experience Platform <2021.1.0.1 allows any authenticated attacker to modify loyalty campaigns and settings, such as fraud prevention, coupon groups, email templates, or referrals.