An issue was discovered in Optimizely Configured Commerce before 5.2.2408. A medium-severity issue concerning business logic exists in the Commerce B2B application, which allows storefront visitors to purchase discontinued products in specific scenarios where requests are altered before reaching the server.
Metrics
Affected Vendors & Products
References
History
Mon, 06 Jan 2025 17:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
cvssV3_1
|
Sat, 04 Jan 2025 02:45:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | An issue was discovered in Optimizely Configured Commerce before 5.2.2408. A medium-severity issue concerning business logic exists in the Commerce B2B application, which allows storefront visitors to purchase discontinued products in specific scenarios where requests are altered before reaching the server. | |
Weaknesses | CWE-472 | |
References |
|
MITRE
Status: PUBLISHED
Assigner: mitre
Published: 2025-01-04T00:00:00
Updated: 2025-01-06T17:02:30.455Z
Reserved: 2025-01-04T00:00:00
Link: CVE-2025-22384
Vulnrichment
Updated: 2025-01-06T17:02:24.462Z
NVD
Status : Awaiting Analysis
Published: 2025-01-04T02:15:06.937
Modified: 2025-01-06T17:15:47.820
Link: CVE-2025-22384
Redhat
No data.