Vulnerability Description
Cezerin v0.33.0 allows unauthorized order-information modification because certain internal attributes can be overwritten via a conflicting name when processing order requests. Hence, a malicious customer can manipulate an order (e.g., its payment status or shipping fee) by adding additional attributes to user-input during the PUT /ajax/cart operation for a checkout, because of getValidDocumentForUpdate in api/server/services/orders/orders.js.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Cezerin | Cezerin | 0.33.0 |
References
- https://github.com/cl0udz/vulnerabilities/blob/master/cezerin-manipulate_order_iExploitThird Party Advisory
- https://github.com/cl0udz/vulnerabilities/blob/master/cezerin-manipulate_order_iExploitThird Party Advisory
FAQ
What is CVE-2019-18608?
CVE-2019-18608 is a vulnerability with a CVSS score of 7.5 (HIGH). Cezerin v0.33.0 allows unauthorized order-information modification because certain internal attributes can be overwritten via a conflicting name when processing order requests. Hence, a malicious cust...
How severe is CVE-2019-18608?
CVE-2019-18608 has been rated HIGH with a CVSS base score of 7.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2019-18608?
Check the references section above for vendor advisories and patch information. Affected products include: Cezerin Cezerin.