CVE-2024-58248 - CERT CVE
ID CVE-2024-58248
Sažetak nopCommerce before 4.80.0 does not offer locking for order placement. Thus there is a race condition with duplicate redeeming of gift cards.
Reference
CVSS
Base: 3.5
Impact: 1.4
Exploitability:1.8
Pristup
VektorSloženostAutentikacija
NETWORK HIGH LOW
Impact
PovjerljivostCjelovitostDostupnost
NONE LOW NONE
CVSS vektor CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:N/I:L/A:N
Zadnje važnije ažuriranje 17-04-2025 - 20:22
Objavljeno 16-04-2025 - 14:15