Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-6pq6-crw9-522h

Опубликовано: 24 мая 2022
Источник: github
Github: Прошло ревью
CVSS3: 7.5

Описание

Cezerin Unauthorized Acces

Cezerin v0.33.0 allows unauthorized order-information modification because certain internal attributes can be overwritten via a conflicting name when processing order requests. Hence, a malicious customer can manipulate an order (e.g., its payment status or shipping fee) by adding additional attributes to user-input during the PUT /ajax/cart operation for a checkout, because of getValidDocumentForUpdate in api/server/services/orders/orders.js.

Пакеты

Наименование

cezerin

npm
Затронутые версииВерсия исправления

<= 0.33.0

Отсутствует

EPSS

Процентиль: 57%
0.00344
Низкий

7.5 High

CVSS3

Дефекты

CWE-20

Связанные уязвимости

CVSS3: 7.5
nvd
больше 6 лет назад

Cezerin v0.33.0 allows unauthorized order-information modification because certain internal attributes can be overwritten via a conflicting name when processing order requests. Hence, a malicious customer can manipulate an order (e.g., its payment status or shipping fee) by adding additional attributes to user-input during the PUT /ajax/cart operation for a checkout, because of getValidDocumentForUpdate in api/server/services/orders/orders.js.

EPSS

Процентиль: 57%
0.00344
Низкий

7.5 High

CVSS3

Дефекты

CWE-20