PT-2024-40043 · Unknown · Legacy Shop Module
Published
2024-05-15
·
Updated
2024-05-15
None
No severity ratings or metrics are available. When they are, we'll update the corresponding info on the page.
Name of the Vulnerable Software and Affected Versions
Legacy shop module (affected versions not specified)
Description
The issue concerns a vulnerability in the Legacy shop module where a backend editor can perform object injection in discount rules. This requires backend access and permission to edit discount rules. Although object injection is a serious issue, the need for specific permissions limits the potential exploiters, typically to administrators.
Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Code Injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Legacy Shop Module