Vulnerability Details CVE-2020-11007
In Shopizer before version 2.11.0, using API or Controller based versions negative quantity is not adequately validated hence creating incorrect shopping cart and order total. This vulnerability makes it possible to create a negative total in the shopping cart. This has been patched in version 2.11.0.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.002
EPSS Ranking 43.1%
CVSS Severity
CVSS v3 Score 6.5
CVSS v2 Score 4.0
Products affected by CVE-2020-11007
-
cpe:2.3:a:shopizer:shopizer:1.1.5
-
cpe:2.3:a:shopizer:shopizer:2.0
-
cpe:2.3:a:shopizer:shopizer:2.0.1
-
cpe:2.3:a:shopizer:shopizer:2.0.2
-
cpe:2.3:a:shopizer:shopizer:2.0.2.1
-
cpe:2.3:a:shopizer:shopizer:2.0.3
-
cpe:2.3:a:shopizer:shopizer:2.0.4
-
cpe:2.3:a:shopizer:shopizer:2.0.5
-
cpe:2.3:a:shopizer:shopizer:2.0.6
-
cpe:2.3:a:shopizer:shopizer:2.10.0
-
cpe:2.3:a:shopizer:shopizer:2.2.0
-
cpe:2.3:a:shopizer:shopizer:2.3.0
-
cpe:2.3:a:shopizer:shopizer:2.4.0
-
cpe:2.3:a:shopizer:shopizer:2.5.0
-
cpe:2.3:a:shopizer:shopizer:2.6.0
-
cpe:2.3:a:shopizer:shopizer:2.7.0
-
cpe:2.3:a:shopizer:shopizer:2.8.0
-
cpe:2.3:a:shopizer:shopizer:2.9.0