CVE-2021-4031

HIGH

Syltek < 10.22.00 - Insufficient Verification of Data Authenticity in Payment System

Title source: llm
STIX 2.1

Description

Syltek application before its 10.22.00 version, does not correctly check that a product ID has a valid payment associated to it. This could allow an attacker to forge a request and bypass the payment system by marking items as payed without any verification.

References (1)

Core 1

Scores

CVSS v3 7.5
EPSS 0.0046
EPSS Percentile 36.1%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N

Details

CWE
CWE-345
Status published
Products (1)
syltek/syltek < 10.22.00
Published Mar 18, 2022
Tracked Since Feb 18, 2026