CVE Feed

    Dashboard / CVE / CVE-2024-53476

    CVE-2024-53476

    A race condition vulnerability in SimplCommerce at commit 230310c8d7a0408569b292c5a805c459d47a1d8f allows attackers to bypass inventory restrictions by simultaneously submitting purchase requests from multiple accounts for the same product. This can lead to overselling when stock is limited, as the system fails to accurately track inventory under high concurrency, resulting in potential loss and unfulfilled orders.

    Published:Dec 27, 2024
    Last Modified:Apr 15, 2026
    EPS:Dec 27, 2024
    EPSS Score:0.00474
    CVSS Score:5.9

    Affected Products

    Vendor
    Simplcommerce
    Product
    Simplcommerce

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High