Описание
An issue was discovered in the NAB Transact extension 2.1.0 for the WooCommerce plugin for WordPress. An online payment system bypass allows orders to be marked as fully paid by assigning an arbitrary bank transaction ID during the payment-details entry step.
Ссылки
- Third Party Advisory
- ExploitMailing ListThird Party Advisory
- ExploitMailing ListThird Party Advisory
- ExploitThird Party Advisory
- Third Party Advisory
- ExploitMailing ListThird Party Advisory
- ExploitMailing ListThird Party Advisory
- ExploitThird Party Advisory
Уязвимые конфигурации
Конфигурация 1
cpe:2.3:a:woocommerce:nab_transact:2.1.0:*:*:*:*:wordpress:*:*
EPSS
Процентиль: 27%
0.00097
Низкий
7.5 High
CVSS3
5 Medium
CVSS2
Дефекты
CWE-354
Связанные уязвимости
github
больше 3 лет назад
An issue was discovered in the NAB Transact extension 2.1.0 for the WooCommerce plugin for WordPress. An online payment system bypass allows orders to be marked as fully paid by assigning an arbitrary bank transaction ID during the payment-details entry step.
EPSS
Процентиль: 27%
0.00097
Низкий
7.5 High
CVSS3
5 Medium
CVSS2
Дефекты
CWE-354