VulnerabilityModified
CVE-2020-11007
This vulnerability makes it possible to create a negative total in the shopping cart.
MEDIUM 6.5EPSS 0.85%
Does this matter?
Lower severity and a low EPSS score (0.85%). Track it; it rarely justifies an emergency change on its own.
Description
In Shopizer before version 2.11.0, using API or Controller based versions negative quantity is not adequately validated hence creating incorrect shopping cart and order total. This vulnerability makes it possible to create a negative total in the shopping cart. This has been patched in version 2.11.0.
- CVSS 3.1
- 6.5 MEDIUMCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N
- EPSS
- 0.85% probability · 56th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-20
- Affected
- shopizer/shopizer
- Source
- security-advisories@github.com
References
- https://github.com/shopizer-ecommerce/shopizer/commit/929ca0839a80c6f4dad087e0259089908787ad2aPatch, Third Party Advisory
- https://github.com/shopizer-ecommerce/shopizer/security/advisories/GHSA-w8rc-pgxq-x2cjThird Party Advisory
- https://github.com/shopizer-ecommerce/shopizer/commit/929ca0839a80c6f4dad087e0259089908787ad2aPatch, Third Party Advisory
- https://github.com/shopizer-ecommerce/shopizer/security/advisories/GHSA-w8rc-pgxq-x2cjThird Party Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.