A business logic vulnerability exists in the Add to Cart function of itsourcecode Agri-Trading Online Shopping System 1.0, which allows remote attackers to manipulate the quant parameter when adding a product to the cart. By setting the quantity value to -0, an attacker can exploit a flaw in the application's total price calculation logic. This vulnerability causes the total price to be reduced to zero, allowing the attacker to add items to the cart and proceed to checkout.
History

Wed, 20 Nov 2024 17:15:00 +0000

Type Values Removed Values Added
First Time appeared Adonesevangelista trading Online Shopping System
CPEs cpe:2.3:a:adonesevangelista:trading_online_shopping_system:1.0:*:*:*:*:*:*:*
Vendors & Products Adonesevangelista trading Online Shopping System
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 15 Nov 2024 20:15:00 +0000

Type Values Removed Values Added
First Time appeared Adonesevangelista
Adonesevangelista agri-trading Online Shopping System
Weaknesses NVD-CWE-noinfo
CPEs cpe:2.3:a:adonesevangelista:agri-trading_online_shopping_system:1.0:*:*:*:*:*:*:*
Vendors & Products Adonesevangelista
Adonesevangelista agri-trading Online Shopping System
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N'}


Thu, 14 Nov 2024 21:45:00 +0000

Type Values Removed Values Added
Description A business logic vulnerability exists in the Add to Cart function of itsourcecode Agri-Trading Online Shopping System 1.0, which allows remote attackers to manipulate the quant parameter when adding a product to the cart. By setting the quantity value to -0, an attacker can exploit a flaw in the application's total price calculation logic. This vulnerability causes the total price to be reduced to zero, allowing the attacker to add items to the cart and proceed to checkout.
References

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published: 2024-11-14T00:00:00

Updated: 2024-11-20T16:15:49.251Z

Reserved: 2024-10-28T00:00:00

Link: CVE-2024-50968

cve-icon Vulnrichment

Updated: 2024-11-20T16:14:04.975Z

cve-icon NVD

Status : Modified

Published: 2024-11-14T22:15:19.900

Modified: 2024-11-20T17:35:28.470

Link: CVE-2024-50968

cve-icon Redhat

No data.