Show filters
3 Total Results
Displaying 1-3 of 3
Sort by:
Attacker Value
Unknown
CVE-2021-31927
Disclosure Date: June 10, 2021 (last updated February 22, 2025)
An Insecure Direct Object Reference (IDOR) vulnerability in Annex Cloud Loyalty Experience Platform <2021.1.0.1 allows any authenticated attacker to modify any existing user, including users assigned to different environments and clients. It was fixed in v2021.1.0.2.
0
Attacker Value
Unknown
CVE-2021-31928
Disclosure Date: June 10, 2021 (last updated November 28, 2024)
Annex Cloud Loyalty Experience Platform <2021.1.0.1 allows any authenticated attacker to escalate privileges to superadministrator. It was fixed in v2021.1.0.2.
0
Attacker Value
Unknown
CVE-2021-31929
Disclosure Date: June 10, 2021 (last updated February 22, 2025)
Annex Cloud Loyalty Experience Platform <2021.1.0.1 allows any authenticated attacker to modify loyalty campaigns and settings, such as fraud prevention, coupon groups, email templates, or referrals.
0