EmbedAI Improper Access Control Vulnerability Allowing Subscription Plan Changes
Vulnerability
A vulnerability allowing improper access control has been identified in EmbedAI versions prior to 2.1. This issue enables authenticated attackers to change their subscription plans without payment by sending a POST request to the '/demos/embedai/pmt_cash_on_delivery/pay' endpoint with modified parameters.
Impact
Exploitation of this vulnerability allows authenticated attackers to fraudulently change their subscription plans without payment.
Remediation
Users can upgrade to EmbedAI version 2.1 or later to address this vulnerability.
Added: Jun 9, 2025, 7:46 PM
Updated: Jun 9, 2025, 7:46 PM
Vulnerability Rating
Custom Algorithm
spread
0.0impact
0.6exploitability
5.2remediation
7.7relevance
0.0threat
0.0urgency
2.9incentive
1.7Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.
