Impact
A race condition exists in the Purchase Stock Handler of awesto django-shop, allowing concurrent inventory updates to interfere with one another. This flaw may yield incorrect stock counts, potentially leading to over‑sales or inventory inconsistencies. The vulnerability is classed as CWE-362, a multi‑threading or concurrency flaw.
Affected Systems
The issue affects the awesto django-shop product, versions up to and including 1.2.4. Users running these or earlier releases should verify the installed version and assess whether the affected Purchase Stock logic is present.
Risk and Exploitability
The calculated CVSS score of 2.3 indicates a low severity, and the EPSS value of less than 1% suggests a very low probability of exploitation. The flaw is remotely exploitable, yet the described high complexity and difficulty of the exploit, coupled with the lack of a KEV listing, keep immediate risk modest. Nonetheless, the public availability of an exploit and the potential for inventory disruption warrant attention.
OpenCVE Enrichment