Syltek application before its 10.22.00 version, does not correctly check that a product ID has a valid payment associated to it. This could allow an attacker to forge a request and bypass the payment system by marking items as payed without any verification.
Fixes

Solution

No solution given by the vendor.


Workaround

This vulnerability has been solved by Playtomic in the in the 10.22.00 version.

History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: INCIBE

Published:

Updated: 2024-09-16T20:11:23.615Z

Reserved: 2021-11-29T00:00:00

Link: CVE-2021-4031

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2022-03-18T18:15:11.697

Modified: 2024-11-21T06:36:45.480

Link: CVE-2021-4031

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.