Security Advisory

CVE-2014-4962

CVE vulnerability detail — eXtreme Datacenter Security Operations

Published 2014-07-15 14:00:00
Last updated 2024-08-06 11:34:36
Assigner mitre
State PUBLISHED

Description

Shopizer 1.1.5 and earlier allows remote attackers to reduce the total cost of their shopping cart via a negative number in the productQuantity parameter, which causes the price of the item to be subtracted from the total cost.