CVE-2020-11007
Summary
| CVE | CVE-2020-11007 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2020-04-16 19:15:00 UTC |
| Updated | 2020-04-29 14:13:00 UTC |
| Description | In Shopizer before version 2.11.0, using API or Controller based versions negative quantity is not adequately validated hence creating incorrect shopping cart and order total. This vulnerability makes it possible to create a negative total in the shopping cart. This has been patched in version 2.11.0. |
Risk And Classification
Problem Types: CWE-20
NVD Known Affected Configurations (CPE 2.3)
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Negative charge in shopping cart · Advisory · shopizer-ecommerce/shopizer · GitHub | CONFIRM | github.com | Third Party Advisory |
| Merge pull request from GHSA-w8rc-pgxq-x2cj · shopizer-ecommerce/shopizer@929ca08 · GitHub | MISC | github.com | Patch, Third Party Advisory |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
Legacy QID Mappings
- 983087 Java (maven) Security Update for com.shopizer:sm-core-model (GHSA-w8rc-pgxq-x2cj)