PT-2024-31952 · Sparkshop · Sparkshop
Published
2024-10-09
·
Updated
2024-10-15
·
CVE-2024-46307
CVSS v3.1
7.5
High
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N |
Name of the Vulnerable Software and Affected Versions
Sparkshop version 1.16
Description
A loop hole in the payment logic of Sparkshop allows attackers to arbitrarily modify the number of products. This is a high-severity issue that affects multiple versions of Sparkshop. Users are urged to update to the latest release to mitigate risks.
Recommendations
For Sparkshop version 1.16, update to the latest release to mitigate risks.
At the moment, there is no information about a newer version that contains a fix for this vulnerability, but updating to the latest version available is recommended.
Exploit
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Sparkshop