CVE-2024-50944
CRITICALSimplCommerce - Integer Overflow in CartController AddToCart Quantity Parameter
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2024-50944. PoCs published by AbdullahAlmutawa.
AI-analyzed exploit summary This repository contains a writeup for CVE-2024-50944, an integer overflow vulnerability in SimplCommerce's cart logic. The vulnerability allows manipulation of product quantities and total prices via crafted quantity parameters.
Description
Integer overflow vulnerability exists in SimplCommerce at commit 230310c8d7a0408569b292c5a805c459d47a1d8f in the shopping cart functionality. The issue lies in the quantity parameter in the CartController's AddToCart method.
Exploits (1)
This repository contains a writeup for CVE-2024-50944, an integer overflow vulnerability in SimplCommerce's cart logic. The vulnerability allows manipulation of product quantities and total prices via crafted quantity parameters.
References (4)
Scores
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H