EmbedAI Improper Access Control Vulnerability Allowing Subscription Plan Changes

Vulnerability

A vulnerability allowing improper access control has been identified in EmbedAI versions prior to 2.1. This issue enables authenticated attackers to change their subscription plans without payment by sending a POST request to the '/demos/embedai/pmt_cash_on_delivery/pay' endpoint with modified parameters.

Impact

Exploitation of this vulnerability allows authenticated attackers to fraudulently change their subscription plans without payment.

Remediation

Users can upgrade to EmbedAI version 2.1 or later to address this vulnerability.

Added: Jun 9, 2025, 7:46 PM
Updated: Jun 9, 2025, 7:46 PM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
0.6
exploitability
5.2
remediation
7.7
relevance
0.0
threat
0.0
urgency
2.9
incentive
1.7

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.