PT-2019-13909 · Woocommerce · Woocommerce Paypal Checkout Payment Gateway

Heibie

·

Publicado

2019-08-29

·

Atualizado

2024-08-05

·

CVE-2019-14979

CVSS v3.1

5.3

Média

VetorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
Name of the Vulnerable Software and Affected Versions WooCommerce PayPal Checkout Payment Gateway plugin version 1.6.17
Description The issue allows for parameter tampering in the amount parameter, such as amount 1, in the cgi-bin/webscr?cmd= cart endpoint. This can be exploited to purchase an item for a lower price than intended. However, the amount is validated against the WooCommerce order total before completing the order. If the amounts do not match, the order will be left in an "On Hold" state.
Recommendations For WooCommerce PayPal Checkout Payment Gateway plugin version 1.6.17, consider validating user input for the amount 1 parameter to prevent tampering, and ensure that the amount is consistent with the WooCommerce order total before completing the order. As a temporary workaround, monitor orders left in an "On Hold" state for potential exploitation attempts.

Exploit

Correção

RCE

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2019-14979

Produtos afetados

Woocommerce Paypal Checkout Payment Gateway