← voltar
CVE-2020-11007mediumCWE-20

Negative charge in shopping cart possible in Shopizer

13Vexday Risk Score

Sem sinal de exploração. Nenhum artefato público de exploração conhecido até agora.

ssvc Trackcvss 6.5epss 0.9%
probabilidade de exploração
0.9%top 45% das CVEs
exploração observada
nãonenhuma fonte reporta
In Shopizer before version 2.11.0, using API or Controller based versions negative quantity is not adequately validated hence creating incorrect shopping cart and order total. This vulnerability makes it possible to create a negative total in the shopping cart. This has been patched in version 2.11.0.
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N