PT-2025-47074 · Bdtask+1 · Bdtask Isshue Multi Store Ecommerce Shopping Cart Solution+1

4M3Rr0R

·

Published

2025-11-16

·

Updated

2025-11-16

·

CVE-2025-13239

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
Name of the Vulnerable Software and Affected Versions Bdtask/CodeCanyon Isshue Multi Store eCommerce Shopping Cart Solution version 5
Description A security issue exists in Bdtask/CodeCanyon Isshue Multi Store eCommerce Shopping Cart Solution version 5. The issue involves manipulation of the argument order in the /submit checkout endpoint, specifically the order total amount and cart total amount parameters, leading to behavioral workflow enforcement. This manipulation can be launched remotely. The exploit has been publicly disclosed.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

RCE

Weakness Enumeration

Related Identifiers

CVE-2025-13239

Affected Products

Codecanyon
Bdtask Isshue Multi Store Ecommerce Shopping Cart Solution