In Shopizer before version 2.11.0, using API or Controller based versions negative quantity is not adequately validated hence creating incorrect shopping cart and order total. This vulnerability makes it possible to create a negative total in the shopping cart. This has been patched in version 2.11.0.
History

No history.

cve-icon MITRE Information

Status: PUBLISHED

Assigner: GitHub_M

Published: 2020-04-16T18:20:12

Updated: 2020-04-16T18:20:12

Reserved: 2020-03-30T00:00:00


Link: CVE-2020-11007

JSON object: View

cve-icon NVD Information

Status : Analyzed

Published: 2020-04-16T19:15:26.400

Modified: 2020-04-29T14:13:03.413


Link: CVE-2020-11007

JSON object: View

cve-icon Redhat Information

No data.

CWE