CVE-2024-50968

CVSS 3.1 Score 7.5 of 10 (high)

Details

Published Nov 14, 2024
Updated: Nov 15, 2024

Summary

CVE-2024-50968 is a business logic vulnerability identified in the Add to Cart function of isourcecode Agri-Trading Online Shopping System 1.0. Attackers can exploit this flaw by manipulating the quant parameter when adding a product to the cart, setting it to -0. The application fails to properly calculate the total price, resulting in it becoming zero. This allows an attacker to add items to the cart with no cost, enabling them to proceed to checkout and potentially gain unauthorized access to discounted or free merchandise.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share