Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2019-18668

Опубликовано: 02 нояб. 2019
Источник: nvd
CVSS3: 6.5
CVSS2: 4
EPSS Низкий

Описание

An issue was discovered in the Currency Switcher addon before 2.11.2 for WooCommerce if a user provides a currency that was not added by the administrator. In this case, even though the currency does not exist, it will be selected, but a price amount will fall back to the default currency. This means that if an attacker provides a currency that does not exist and is worth less than this default, the attacker can eventually purchase an item for a significantly cheaper price.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:wpwham:currency_switcher_for_woocommerce:*:*:*:*:*:wordpress:*:*
Версия до 2.11.2 (исключая)

EPSS

Процентиль: 76%
0.00942
Низкий

6.5 Medium

CVSS3

4 Medium

CVSS2

Дефекты

CWE-755

Связанные уязвимости

CVSS3: 6.5
github
больше 3 лет назад

An issue was discovered in the Currency Switcher addon before 2.11.2 for WooCommerce if a user provides a currency that was not added by the administrator. In this case, even though the currency does not exist, it will be selected, but a price amount will fall back to the default currency. This means that if an attacker provides a currency that does not exist and is worth less than this default, the attacker can eventually purchase an item for a significantly cheaper price.

EPSS

Процентиль: 76%
0.00942
Низкий

6.5 Medium

CVSS3

4 Medium

CVSS2

Дефекты

CWE-755