Home
Trends
Vulnerabilities
News
Researchers
Why dbugs?

Password

Researcher fromCVE Assignment Team
#35032of 53,608
7.5Total CVSS
Vulnerabilities · 1
PT-2018-18617
7.5
2018-03-19
Yxcms · Yxcms · CVE-2018-8761
**Name of the Vulnerable Software and Affected Versions** Yxcms building system (compatible cell phone) version 1.4.7 **Description** The issue is related to a logic flaw in the `shopcarController.php` file, which allows attackers to modify prices by analyzing data from packet captures before form submission. **Recommendations** For version 1.4.7, consider implementing input validation and sanitization to prevent unauthorized price modifications. As a temporary workaround, restrict access to the `shopcarController.php` file to minimize the risk of exploitation.