Syltek application before its 10.22.00 version, does not correctly check that a product ID has a valid payment associated to it. This could allow an attacker to forge a request and bypass the payment system by marking items as payed without any verification.
Metrics
Affected Vendors & Products
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2021-33932 | Syltek application before its 10.22.00 version, does not correctly check that a product ID has a valid payment associated to it. This could allow an attacker to forge a request and bypass the payment system by marking items as payed without any verification. |
Fixes
Solution
No solution given by the vendor.
Workaround
This vulnerability has been solved by Playtomic in the in the 10.22.00 version.
References
History
No history.
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: INCIBE
Published:
Updated: 2024-09-16T20:11:23.615Z
Reserved: 2021-11-29T00:00:00
Link: CVE-2021-4031
No data.
Status : Modified
Published: 2022-03-18T18:15:11.697
Modified: 2024-11-21T06:36:45.480
Link: CVE-2021-4031
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD