CVE-2024-2151
SourceCodester Online Mobile Management Store Product Price logic error
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
2Exploited in Wild
-Decision
Descriptions
A vulnerability classified as problematic was found in SourceCodester Online Mobile Management Store 1.0. Affected by this vulnerability is an unknown functionality of the component Product Price Handler. The manipulation of the argument quantity with the input -1 leads to business logic errors. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-255583.
Una vulnerabilidad fue encontrada en SourceCodester Online Mobile Management Store 1.0 y clasificada como problemática. Una función desconocida del componente Product Price Handler es afectada por esta vulnerabilidad. La manipulación del argumento cantidad con la entrada -1 provoca errores de lógica empresarial. El ataque se puede lanzar de forma remota. El exploit ha sido divulgado al público y puede utilizarse. El identificador asociado de esta vulnerabilidad es VDB-255583.
In SourceCodester Online Mobile Management Store 1.0 wurde eine problematische Schwachstelle entdeckt. Dabei geht es um eine nicht genauer bekannte Funktion der Komponente Product Price Handler. Durch das Beeinflussen des Arguments quantity mit der Eingabe -1 mit unbekannten Daten kann eine business logic errors-Schwachstelle ausgenutzt werden. Die Umsetzung des Angriffs kann dabei über das Netzwerk erfolgen. Der Exploit steht zur öffentlichen Verfügung.
CVSS Scores
SSVC
- Decision:Track*
Timeline
- 2024-03-03 CVE Reserved
- 2024-03-03 CVE Published
- 2024-03-04 EPSS Updated
- 2024-06-23 First Exploit
- 2024-08-23 CVE Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
CWE
- CWE-840: Business Logic Errors
CAPEC
References (3)
URL | Tag | Source |
---|---|---|
https://vuldb.com/?id.255583 | Technical Description |
URL | Date | SRC |
---|---|---|
https://github.com/bigb0x/CVE-2024-21514 | 2024-06-23 | |
https://github.com/vanitashtml/CVE-Dumps/blob/main/Business%20Logic%20in%20Mobile%20Management%20Store.md | 2024-08-23 |
URL | Date | SRC |
---|
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
SourceCodester Search vendor "SourceCodester" | Online Mobile Management Store Search vendor "SourceCodester" for product "Online Mobile Management Store" | 1.0 Search vendor "SourceCodester" for product "Online Mobile Management Store" and version "1.0" | en |
Affected
|