Home
Trends
Vulnerabilities
News
Researchers
Why dbugs?

Yannick Gosset

Researcher fromAix-Marseille University
#41354of 53,632
6.5Total CVSS
Vulnerabilities · 1
PT-2020-12488
6.5
2020-04-16
Shopizer · Shopizer · CVE-2020-11007
**Name of the Vulnerable Software and Affected Versions** Shopizer versions prior to 2.11.0 **Description** The issue arises from inadequate validation of negative quantity when using API or Controller based versions, leading to incorrect shopping cart and order totals. This allows for the creation of a negative total in the shopping cart. **Recommendations** For versions prior to 2.11.0, update to version 2.11.0 to resolve the issue.