Description
Syltek application before its 10.22.00 version, does not correctly check that a product ID has a valid payment associated to it. This could allow an attacker to forge a request and bypass the payment system by marking items as payed without any verification.
Published: 2022-03-18
Score: 7.5 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

No analysis available yet.

Remediation

Vendor Workaround

This vulnerability has been solved by Playtomic in the in the 10.22.00 version.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2021-33932 Syltek application before its 10.22.00 version, does not correctly check that a product ID has a valid payment associated to it. This could allow an attacker to forge a request and bypass the payment system by marking items as payed without any verification.
History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: INCIBE

Published:

Updated: 2024-09-16T20:11:23.615Z

Reserved: 2021-11-29T00:00:00.000Z

Link: CVE-2021-4031

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2022-03-18T18:15:11.697

Modified: 2024-11-21T06:36:45.480

Link: CVE-2021-4031

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses