PT-2024-18924 · Sourcecodester · Sourcecodester Online Mobile Management Store

Rjavenido22

·

Published

2024-03-03

·

Updated

2024-12-20

·

CVE-2024-2151

CVSS v3.1

5.3

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
Name of the Vulnerable Software and Affected Versions SourceCodester Online Mobile Management Store version 1.0
Description A problematic vulnerability was found in the component Product Price Handler of the SourceCodester Online Mobile Management Store. The manipulation of the quantity argument with the input -1 leads to business logic errors. The attack can be launched remotely.
Recommendations For version 1.0, consider restricting the input of the quantity argument to prevent business logic errors until a patch is available. As a temporary workaround, avoid using negative values for the quantity argument in the affected component.

Exploit

Fix

Weakness Enumeration

Related Identifiers

CVE-2024-2151

Affected Products

Sourcecodester Online Mobile Management Store