PT-2024-40043 · Unknown · Legacy Shop Module

Published

2024-05-15

·

Updated

2024-05-15

None

No severity ratings or metrics are available. When they are, we'll update the corresponding info on the page.
Name of the Vulnerable Software and Affected Versions Legacy shop module (affected versions not specified)
Description The issue concerns a vulnerability in the Legacy shop module where a backend editor can perform object injection in discount rules. This requires backend access and permission to edit discount rules. Although object injection is a serious issue, the need for specific permissions limits the potential exploiters, typically to administrators.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Code Injection

Weakness Enumeration

Related Identifiers

GHSA-39J2-4P9J-5W4J

Affected Products

Legacy Shop Module