Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-cxrr-phf8-4pfv

Опубликовано: 24 мая 2022
Источник: github
Github: Не прошло ревью
CVSS3: 6.5

Описание

An issue was discovered in the Currency Switcher addon before 2.11.2 for WooCommerce if a user provides a currency that was not added by the administrator. In this case, even though the currency does not exist, it will be selected, but a price amount will fall back to the default currency. This means that if an attacker provides a currency that does not exist and is worth less than this default, the attacker can eventually purchase an item for a significantly cheaper price.

An issue was discovered in the Currency Switcher addon before 2.11.2 for WooCommerce if a user provides a currency that was not added by the administrator. In this case, even though the currency does not exist, it will be selected, but a price amount will fall back to the default currency. This means that if an attacker provides a currency that does not exist and is worth less than this default, the attacker can eventually purchase an item for a significantly cheaper price.

EPSS

Процентиль: 76%
0.00993
Низкий

6.5 Medium

CVSS3

Дефекты

CWE-20
CWE-755

Связанные уязвимости

CVSS3: 6.5
nvd
больше 6 лет назад

An issue was discovered in the Currency Switcher addon before 2.11.2 for WooCommerce if a user provides a currency that was not added by the administrator. In this case, even though the currency does not exist, it will be selected, but a price amount will fall back to the default currency. This means that if an attacker provides a currency that does not exist and is worth less than this default, the attacker can eventually purchase an item for a significantly cheaper price.

EPSS

Процентиль: 76%
0.00993
Низкий

6.5 Medium

CVSS3

Дефекты

CWE-20
CWE-755