First published: Thu May 19 2022(Updated: )
Improper input validation vulnerability in Mangboard commerce package could lead to occur for abnormal request. A remote attacker can exploit this vulnerability to manipulate the total order amount into a negative number and then pay for the order.
Credit: vuln@krcert.or.kr
Affected Software | Affected Version | How to fix |
---|---|---|
Mangboard Commerce | <1.3.9 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID for this issue is CVE-2021-26631.
This vulnerability could allow a remote attacker to manipulate the total order amount and pay for the order using a negative number, which could result in financial loss for the affected system.
The Mangboard commerce package versions up to and excluding 1.3.9 are affected by this vulnerability.
The severity of this vulnerability is considered high with a CVSS score of 7.5.
There is currently no information available about a fix for this vulnerability. It is recommended to follow the guidance provided by the software vendor or security advisory.