PT-2020-12488 · Shopizer · Shopizer
Yannick Gosset
·
Published
2020-04-16
·
Updated
2020-04-29
·
CVE-2020-11007
CVSS v3.1
6.5
Medium
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N |
Name of the Vulnerable Software and Affected Versions
Shopizer versions prior to 2.11.0
Description
The issue arises from inadequate validation of negative quantity when using API or Controller based versions, leading to incorrect shopping cart and order totals. This allows for the creation of a negative total in the shopping cart.
Recommendations
For versions prior to 2.11.0, update to version 2.11.0 to resolve the issue.
Fix
RCE
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Shopizer