Impact
Shopper, a headless e‑commerce administration interface, allows administrators to enter fixed‑amount discounts with negative values through its cpanel/discounts page. These values are persisted without validation and are subsequently used by the order calculation pipeline. Since the pipeline subtracts the discount amount from the subtotal, a negative discount inflates the order total rather than reducing it. The vulnerability is a classic input validation weakness (CWE‑20). It does not provide a direct code execution or denial‑of‑service capability, but it can lead to incorrect pricing and financial data integrity failures for each order that consumes a negative discount.
Affected Systems
All ShopperLabs Shopper releases prior to version 2.9.0 are affected. The product is the Headless e‑commerce Admin Panel published by ShopperLabs. Any installation using a pre‑2.9.0 build that has not applied the 2.9.0 fix and that retains the administrative discounts interface is potentially vulnerable.
Risk and Exploitability
The base CVSS score of 6.5 reflects moderate severity; the EPSS score of less than 1 % indicates a very low likelihood of exploitation, and it is not listed in the CISA KEV catalog. Based on the description, exploitation requires authenticated access to the administrative discounts page. Once a negative discount record is created, the application processes it unconditionally, yielding inflated totals. Because the flaw resides in a non‑publicly accessible interface and does not provide arbitrary code execution, the overall risk is confined to potential financial loss rather than broader system compromise.
OpenCVE Enrichment
Github GHSA