CVE Feed

    Dashboard / CVE / CVE-2024-50968

    CVE-2024-50968

    A business logic vulnerability exists in the Add to Cart function of itsourcecode Agri-Trading Online Shopping System 1.0, which allows remote attackers to manipulate the quant parameter when adding a product to the cart. By setting the quantity value to -0, an attacker can exploit a flaw in the application's total price calculation logic. This vulnerability causes the total price to be reduced to zero, allowing the attacker to add items to the cart and proceed to checkout.

    Published:Nov 14, 2024
    Last Modified:Nov 20, 2024
    EPS:Nov 14, 2024
    EPSS Score:0.03337
    CVSS Score:7.5

    Affected Products

    Vendor
    Adonesevangelista
    Product
    Agri-trading Online Shopping System
    Vendor
    Adonesevangelista
    Product
    Trading Online Shopping System

    Common Weakness Enumeration

    No CWE recorded yet

    Common Attack Pattern Enumeration and Classification (CAPEC)

    No CAPEC recorded yet

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High