Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2026-56831

Опубликовано: 15 сент. 2026
Источник: nvd
CVSS3: 6.5
EPSS Низкий

Описание

Shopper is a Headless e-commerce Admin Panel. Prior to 2.9.0, the /cpanel/discounts administrative interface accepts negative fixed_amount discount values, persists them in sh_discounts, and passes them through vendor/shopper/cart/src/Discounts/DiscountCalculator.php and vendor/shopper/cart/src/Pipelines/Calculate.php without enforcing a positive-value invariant. Because the calculation subtracts discountTotal from the subtotal, a negative discount increases the resulting order total instead of reducing it. Malformed discount records can therefore cause incorrect pricing and financial data integrity failures, although the advisory does not establish a customer-facing exploitation path. This issue is fixed in version 2.9.0.

EPSS

Процентиль: 34%
0.00406
Низкий

6.5 Medium

CVSS3

Дефекты

CWE-20

Связанные уязвимости

CVSS3: 6.5
github
8 дней назад

Shopper: Negative discount values accepted and propagated through order calculation pipeline

EPSS

Процентиль: 34%
0.00406
Низкий

6.5 Medium

CVSS3

Дефекты

CWE-20