A business logic vulnerability exists in the Add to Cart function of itsourcecode Agri-Trading Online Shopping System 1.0, which allows remote attackers to manipulate the quant parameter when adding a product to the cart. By setting the quantity value to -0, an attacker can exploit a flaw in the application's total price calculation logic. This vulnerability causes the total price to be reduced to zero, allowing the attacker to add items to the cart and proceed to checkout.
Metrics
Affected Vendors & Products
References
Link | Providers |
---|---|
https://github.com/Akhlak2511/CVE-2024-50968 |
History
Wed, 20 Nov 2024 17:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
Adonesevangelista trading Online Shopping System
|
|
CPEs | cpe:2.3:a:adonesevangelista:trading_online_shopping_system:1.0:*:*:*:*:*:*:* | |
Vendors & Products |
Adonesevangelista trading Online Shopping System
|
|
Metrics |
ssvc
|
Fri, 15 Nov 2024 20:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
Adonesevangelista
Adonesevangelista agri-trading Online Shopping System |
|
Weaknesses | NVD-CWE-noinfo | |
CPEs | cpe:2.3:a:adonesevangelista:agri-trading_online_shopping_system:1.0:*:*:*:*:*:*:* | |
Vendors & Products |
Adonesevangelista
Adonesevangelista agri-trading Online Shopping System |
|
Metrics |
cvssV3_1
|
Thu, 14 Nov 2024 21:45:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | A business logic vulnerability exists in the Add to Cart function of itsourcecode Agri-Trading Online Shopping System 1.0, which allows remote attackers to manipulate the quant parameter when adding a product to the cart. By setting the quantity value to -0, an attacker can exploit a flaw in the application's total price calculation logic. This vulnerability causes the total price to be reduced to zero, allowing the attacker to add items to the cart and proceed to checkout. | |
References |
|
MITRE
Status: PUBLISHED
Assigner: mitre
Published: 2024-11-14T00:00:00
Updated: 2024-11-20T16:15:49.251Z
Reserved: 2024-10-28T00:00:00
Link: CVE-2024-50968
Vulnrichment
Updated: 2024-11-20T16:14:04.975Z
NVD
Status : Modified
Published: 2024-11-14T22:15:19.900
Modified: 2024-11-20T17:35:28.470
Link: CVE-2024-50968
Redhat
No data.