CVE-2024-53476
CVE-2024-53476
Título es
CVE-2024-53476
Vie, 27/12/2024 – 19:15
Gravedad 2.0 Txt
Pendiente de análisis
Título en
CVE-2024-53476
Descripción en
A race condition vulnerability in SimplCommerce at commit 230310c8d7a0408569b292c5a805c459d47a1d8f allows attackers to bypass inventory restrictions by simultaneously submitting purchase requests from multiple accounts for the same product. This can lead to overselling when stock is limited, as the system fails to accurately track inventory under high concurrency, resulting in potential loss and unfulfilled orders.
27/12/2024
27/12/2024
Gravedad 3.1 Txt Gravedad 3.1 (CVSS 3.1 Base Score)
Pendiente de análisis
Referencias
Enviar en el boletín
Off