Описание
Microweber vulnerable to Improper Validation of Specified Quantity in Input
Microweber prior to version 1.2.11 can have a negative product amount. This could allow an attacker to manipulate the total value and get products for free.
Пакеты
Наименование
microweber/microweber
composer
Затронутые версииВерсия исправления
< 1.2.11
1.2.11
Связанные уязвимости
CVSS3: 4.3
nvd
почти 4 года назад
Improper Validation of Specified Quantity in Input in Packagist microweber/microweber prior to 1.2.11.