CVE-2024-46307
CVSS 3.1 Score 7.5 of 10 (high)
Details
Published Oct 9, 2024
Updated: Oct 15, 2024
CWE ID 841
Summary
CVE-2024-46307 is a newly disclosed vulnerability affecting Sparkshop version 1.16. The issue involves a flaw in the payment logic, which enables attackers to manipulate the number of products arbitrarily during transactions. This vulnerability can potentially lead to financial loss or unauthorized access to customer information. Attackers can exploit this bug to bypass payment constraints, resulting in overcharging or unintended purchases. It is recommended that users of Sparkshop v1.16 upgrade to a patched version as soon as possible to mitigate this risk.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.