Show plain JSON{"dataType": "CVE_RECORD", "dataVersion": "5.1", "cveMetadata": {"cveId": "CVE-2024-2151", "assignerOrgId": "1af790b2-7ee1-4545-860a-a788eba489b5", "state": "PUBLISHED", "assignerShortName": "VulDB", "dateReserved": "2024-03-03T16:01:13.354Z", "datePublished": "2024-03-03T23:31:04.610Z", "dateUpdated": "2024-08-23T20:44:06.322Z"}, "containers": {"cna": {"providerMetadata": {"orgId": "1af790b2-7ee1-4545-860a-a788eba489b5", "shortName": "VulDB", "dateUpdated": "2024-03-03T23:31:04.610Z"}, "title": "SourceCodester Online Mobile Management Store Product Price logic error", "problemTypes": [{"descriptions": [{"type": "CWE", "cweId": "CWE-840", "lang": "en", "description": "CWE-840 Business Logic Errors"}]}], "affected": [{"vendor": "SourceCodester", "product": "Online Mobile Management Store", "versions": [{"version": "1.0", "status": "affected"}], "modules": ["Product Price Handler"]}], "descriptions": [{"lang": "en", "value": "A vulnerability classified as problematic was found in SourceCodester Online Mobile Management Store 1.0. Affected by this vulnerability is an unknown functionality of the component Product Price Handler. The manipulation of the argument quantity with the input -1 leads to business logic errors. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-255583."}, {"lang": "de", "value": "In SourceCodester Online Mobile Management Store 1.0 wurde eine problematische Schwachstelle entdeckt. Dabei geht es um eine nicht genauer bekannte Funktion der Komponente Product Price Handler. Durch das Beeinflussen des Arguments quantity mit der Eingabe -1 mit unbekannten Daten kann eine business logic errors-Schwachstelle ausgenutzt werden. Die Umsetzung des Angriffs kann dabei \u00fcber das Netzwerk erfolgen. Der Exploit steht zur \u00f6ffentlichen Verf\u00fcgung."}], "metrics": [{"cvssV3_1": {"version": "3.1", "baseScore": 4.3, "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N", "baseSeverity": "MEDIUM"}}, {"cvssV3_0": {"version": "3.0", "baseScore": 4.3, "vectorString": "CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N", "baseSeverity": "MEDIUM"}}, {"cvssV2_0": {"version": "2.0", "baseScore": 4, "vectorString": "AV:N/AC:L/Au:S/C:N/I:P/A:N"}}], "timeline": [{"time": "2024-03-03T00:00:00.000Z", "lang": "en", "value": "Advisory disclosed"}, {"time": "2024-03-03T01:00:00.000Z", "lang": "en", "value": "VulDB entry created"}, {"time": "2024-03-03T17:06:28.000Z", "lang": "en", "value": "VulDB entry last update"}], "credits": [{"lang": "en", "value": "rjavenido22 (VulDB User)", "type": "reporter"}], "references": [{"url": "https://vuldb.com/?id.255583", "name": "VDB-255583 | SourceCodester Online Mobile Management Store Product Price logic error", "tags": ["vdb-entry", "technical-description"]}, {"url": "https://vuldb.com/?ctiid.255583", "name": "VDB-255583 | CTI Indicators (IOB, IOC, IOA)", "tags": ["signature", "permissions-required"]}, {"url": "https://github.com/vanitashtml/CVE-Dumps/blob/main/Business%20Logic%20in%20Mobile%20Management%20Store.md", "tags": ["exploit"]}]}, "adp": [{"providerMetadata": {"orgId": "af854a3a-2127-422b-91ae-364da2661108", "shortName": "CVE", "dateUpdated": "2024-08-01T19:03:39.039Z"}, "title": "CVE Program Container", "references": [{"url": "https://vuldb.com/?id.255583", "name": "VDB-255583 | SourceCodester Online Mobile Management Store Product Price logic error", "tags": ["vdb-entry", "technical-description", "x_transferred"]}, {"url": "https://vuldb.com/?ctiid.255583", "name": "VDB-255583 | CTI Indicators (IOB, IOC, IOA)", "tags": ["signature", "permissions-required", "x_transferred"]}, {"url": "https://github.com/vanitashtml/CVE-Dumps/blob/main/Business%20Logic%20in%20Mobile%20Management%20Store.md", "tags": ["exploit", "x_transferred"]}]}, {"affected": [{"vendor": "sourcecodester", "product": "online_mobile_management_store", "cpes": ["cpe:2.3:a:sourcecodester:online_mobile_management_store:1.0:*:*:*:*:*:*:*"], "defaultStatus": "unknown", "versions": [{"version": "1.0", "status": "affected"}]}], "metrics": [{"other": {"type": "ssvc", "content": {"timestamp": "2024-08-23T20:43:15.495183Z", "id": "CVE-2024-2151", "options": [{"Exploitation": "poc"}, {"Automatable": "no"}, {"Technical Impact": "partial"}], "role": "CISA Coordinator", "version": "2.0.3"}}}], "title": "CISA ADP Vulnrichment", "providerMetadata": {"orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0", "shortName": "CISA-ADP", "dateUpdated": "2024-08-23T20:44:06.322Z"}}]}}