A race condition vulnerability in SimplCommerce at commit 230310c8d7a0408569b292c5a805c459d47a1d8f allows attackers to bypass inventory restrictions by simultaneously submitting purchase requests from multiple accounts for the same product. This can lead to overselling when stock is limited, as the system fails to accurately track inventory under high concurrency, resulting in potential loss and unfulfilled orders.
Metrics
Affected Vendors & Products
References
History
Sat, 28 Dec 2024 19:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Weaknesses | CWE-362 | |
Metrics |
cvssV3_1
|
Fri, 27 Dec 2024 19:00:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | A race condition vulnerability in SimplCommerce at commit 230310c8d7a0408569b292c5a805c459d47a1d8f allows attackers to bypass inventory restrictions by simultaneously submitting purchase requests from multiple accounts for the same product. This can lead to overselling when stock is limited, as the system fails to accurately track inventory under high concurrency, resulting in potential loss and unfulfilled orders. | |
References |
|
MITRE
Status: PUBLISHED
Assigner: mitre
Published: 2024-12-27T00:00:00
Updated: 2024-12-28T18:22:23.419Z
Reserved: 2024-11-20T00:00:00
Link: CVE-2024-53476
Vulnrichment
Updated: 2024-12-28T18:22:17.849Z
NVD
Status : Awaiting Analysis
Published: 2024-12-27T19:15:09.103
Modified: 2024-12-28T19:15:06.880
Link: CVE-2024-53476
Redhat
No data.