PT-2020-12488 · Shopizer · Shopizer

Yannick Gosset

·

Published

2020-04-16

·

Updated

2020-04-29

·

CVE-2020-11007

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N
Name of the Vulnerable Software and Affected Versions Shopizer versions prior to 2.11.0
Description The issue arises from inadequate validation of negative quantity when using API or Controller based versions, leading to incorrect shopping cart and order totals. This allows for the creation of a negative total in the shopping cart.
Recommendations For versions prior to 2.11.0, update to version 2.11.0 to resolve the issue.

Fix

RCE

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2020-11007
GHSA-W8RC-PGXQ-X2CJ

Affected Products

Shopizer