Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
CVE-2023-36643 — Proof-of-concept for CVE-2023-36643: an incorrect access control vulnerability in ITB-GmbH TradePro v9.5 that allows remote attackers to enumerate and retrieve all shop orders via an unauthenticated HTTP endpoint. | Kitploit
Tools/GitHubGitHub/caffeinated-labs/cve-2023-36643
Vulnerability AnalysisInformation GatheringWeb SecurityPenetration TestingMisconfiguration
GitHubcaffeinated-labs/cve-2023-36643

CVE-2023-36643

Proof-of-concept for CVE-2023-36643: an incorrect access control vulnerability in ITB-GmbH TradePro v9.5 that allows remote attackers to enumerate and retrieve all shop orders via an unauthenticated HTTP endpoint.

View Repository
Website
42 years agoNot yet reviewed

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
Share

== Affected Software [%hardbreaks] Vendor: ITB-GmbH Affected Products: TradePro (v9.5) Component: Function Customer; Action oordershow Confirmed: yes

== Attack Vector [%hardbreaks] Type: Incorrect Access Control Access-Type: Remote Impact: Information Disclosure

Incorrect Access Control in function customer, action oordershow in ITB-GmbH TradePro v9.5 allows remote attackers to receive all orders from the online shop by passing arbitrary order numbers to an http(s) endpoint.

== Description The bestellid should be known beforehand but can be enumerated easily or by using an SQLi (see Report link:/security/CVE-2023-36645[CVE-2023-36645])

Calling http(s)://[DOMAIN]/shop/de/sys/?func=customer&action=oordershow&wkid=[COOKIE]&bestellid=[BESTELL_ID] with a valid but unauthenticated session cookie gives the attacker access to all orders.

== CVSS [%hardbreaks] Score: 7.1 Vector: https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N/E:P[CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N/E:P]

== Credits

  • Lynn
  • Jadyn
  • ]
https://zerforschung.org[zerforschung.org
Download Tool