PT-2023-32783 · Microweber · Microweber
Published
2023-12-14
·
Updated
2023-12-21
·
CVE-2023-6832
CVSS v3.1
6.0
Medium
| Vector | AV:N/AC:H/PR:H/UI:R/S:U/C:H/I:H/A:L |
Name of the Vulnerable Software and Affected Versions
microweber/microweber versions prior to 2.0
Description
A vulnerability has been identified in microweber where users can exploit business logic errors to obtain items at a lower price. This occurs when the admin disables the use of the coupon code functionality, but the user sends requests to the API that handles the coupon code.
Recommendations
For versions prior to 2.0, update to version 2.0 or later to resolve the issue. As a temporary workaround, consider disabling the coupon code functionality entirely to prevent exploitation. Restrict access to the API endpoint that handles coupon codes to minimize the risk of exploitation. Avoid using the coupon code functionality in the affected API endpoint until the issue is resolved.
Exploit
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Microweber