Vulnerability Details CVE-2014-4962
Shopizer 1.1.5 and earlier allows remote attackers to reduce the total cost of their shopping cart via a negative number in the productQuantity parameter, which causes the price of the item to be subtracted from the total cost.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.037
EPSS Ranking 87.4%
CVSS Severity
CVSS v2 Score 6.4
Products affected by CVE-2014-4962
-
cpe:2.3:a:shopizer:shopizer:1.1.5