PT-2022-13418 · Unknown · Microweber

Published

2022-02-26

·

Updated

2023-08-02

·

CVE-2022-0762

CVSS v3.1

5.5

Medium

VectorAV:N/AC:L/PR:L/UI:R/S:U/C:L/I:L/A:L
Name of the Vulnerable Software and Affected Versions microweber versions prior to 1.3
Description The issue concerns business logic errors and incorrect authorization in the microweber repository. This allows users to add deleted products to a cart and buy them, exposing resources to the wrong sphere.
Recommendations For versions prior to 1.3, update to version 1.3 or later to resolve the issue. As a temporary workaround, consider restricting access to the cart functionality for deleted products until a patch is available. Avoid using the affected repository until the issue is resolved.

Exploit

Fix

Incorrect Authorization

Exposure of Resource to Wrong Sphere

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2022-0762
GHSA-5875-P652-2PPM

Affected Products

Microweber