Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-xcww-23jc-699x

Опубликовано: 10 сент. 2025
Источник: github
Github: Не прошло ревью
CVSS4: 1.2
CVSS3: 2.6

Описание

A vulnerability was detected in GrandNode up to 2.3.0. The impacted element is an unknown function of the file /checkout/ConfirmOrder/ of the component Voucher Handler. The manipulation of the argument giftvouchercouponcode results in race condition. The attack may be launched remotely. The attack requires a high level of complexity. The exploitability is regarded as difficult. The vendor was contacted early about this disclosure but did not respond in any way.

A vulnerability was detected in GrandNode up to 2.3.0. The impacted element is an unknown function of the file /checkout/ConfirmOrder/ of the component Voucher Handler. The manipulation of the argument giftvouchercouponcode results in race condition. The attack may be launched remotely. The attack requires a high level of complexity. The exploitability is regarded as difficult. The vendor was contacted early about this disclosure but did not respond in any way.

EPSS

Процентиль: 4%
0.00017
Низкий

1.2 Low

CVSS4

2.6 Low

CVSS3

Дефекты

CWE-362

Связанные уязвимости

CVSS3: 2.6
nvd
5 месяцев назад

A vulnerability was detected in GrandNode up to 2.3.0. The impacted element is an unknown function of the file /checkout/ConfirmOrder/ of the component Voucher Handler. The manipulation of the argument giftvouchercouponcode results in race condition. The attack may be launched remotely. The attack requires a high level of complexity. The exploitability is regarded as difficult. The vendor was contacted early about this disclosure but did not respond in any way.

EPSS

Процентиль: 4%
0.00017
Низкий

1.2 Low

CVSS4

2.6 Low

CVSS3

Дефекты

CWE-362