VYPR
Unrated severityNVD Advisory· Published Jun 10, 2021· Updated Aug 3, 2024

CVE-2021-31929

CVE-2021-31929

Description

Annex Cloud Loyalty Experience Platform <2021.1.0.1 allows any authenticated attacker to modify loyalty campaigns and settings, such as fraud prevention, coupon groups, email templates, or referrals.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Annex Cloud Loyalty Experience Platform before version 2021.1.0.1 allows any authenticated attacker to modify loyalty campaigns and settings, including fraud prevention, coupon groups, email templates, and referrals.

Vulnerability

Annex Cloud Loyalty Experience Platform versions prior to 2021.1.0.1 contain an access control vulnerability. Any authenticated user can modify loyalty campaigns and settings, such as fraud prevention, coupon groups, email templates, or referrals. The vulnerability exists in the platform's administrative functionality, where insufficient authorization checks allow authenticated users to perform modifications that should be restricted to higher-privileged roles.

Exploitation

An attacker needs valid credentials for any user account on the Annex Cloud Loyalty Experience Platform. With those credentials, the attacker can access the administrative interface and modify various loyalty program configurations, including fraud prevention rules, coupon groups, email templates, and referral settings. No additional privileges or user interaction is required beyond authentication.

Impact

Successful exploitation allows the attacker to alter critical loyalty program settings, potentially leading to unauthorized coupon generation, modification of email templates (which could be used for phishing), disabling fraud prevention measures, or manipulating referral programs. This could result in financial loss, reputational damage, and compromise of the loyalty platform's integrity.

Mitigation

The vulnerability is fixed in Annex Cloud Loyalty Experience Platform version 2021.1.0.1. Organizations should upgrade to this version or later. No workarounds are documented in the available references. If upgrading is not immediately possible, administrators should review and restrict user permissions to the minimum necessary.

AI Insight generated on May 27, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

2

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

2

News mentions

0

No linked articles in our index yet.