Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2021-26631

Опубликовано: 19 мая 2022
Источник: nvd
CVSS3: 8
CVSS3: 7.5
CVSS2: 5
EPSS Низкий

Описание

Improper input validation vulnerability in Mangboard commerce package could lead to occur for abnormal request. A remote attacker can exploit this vulnerability to manipulate the total order amount into a negative number and then pay for the order.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:mangboard:commerce:*:*:*:*:*:*:*:*
Версия до 1.3.9 (исключая)

EPSS

Процентиль: 56%
0.00334
Низкий

8 High

CVSS3

7.5 High

CVSS3

5 Medium

CVSS2

Дефекты

CWE-20
CWE-20

Связанные уязвимости

CVSS3: 7.5
github
больше 3 лет назад

Improper input validation vulnerability in Mangboard commerce package could lead to occur for abnormal request. A remote attacker can exploit this vulnerability to manipulate the total order amount into a negative number and then pay for the order.

EPSS

Процентиль: 56%
0.00334
Низкий

8 High

CVSS3

7.5 High

CVSS3

5 Medium

CVSS2

Дефекты

CWE-20
CWE-20