Improper access control allows editors to remove required records
Package
Affected versions
2024.04.1
>= 2023.04.1, < 2023.10.4
>= 2022.04.1, < 2022.10.3
>= 2021.04.1, < 2021.10.6
< 2020.10.13
Patched versions
2024.04.2
2023.10.4
2022.10.3
2021.10.6
2020.10.13
Impact
Improper access control allows editors to remove admin group and locale configuration in Aimeos backend