Vendor
The cc-connect application through version 1.5.0 contains an authorization bypass vulnerability in the onCardAction handler, allowing unprivileged users to execute unauthorized agent commands.