CVE-2024-50968

HIGH

iSourcecode Agri-Trading Online Shopping System 1.0 - Info Disclosure

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2024-50968. PoCs published by Akhlak2511.

AI-analyzed exploit summary This repository contains a detailed writeup describing a business logic vulnerability in itsourcecode Agri-Trading Online Shopping System 1.0. The vulnerability allows attackers to manipulate the 'quant' parameter to set the total price to zero by using a value of -0.

Description

A business logic vulnerability exists in the Add to Cart function of itsourcecode Agri-Trading Online Shopping System 1.0, which allows remote attackers to manipulate the quant parameter when adding a product to the cart. By setting the quantity value to -0, an attacker can exploit a flaw in the application's total price calculation logic. This vulnerability causes the total price to be reduced to zero, allowing the attacker to add items to the cart and proceed to checkout.

Exploits (1)

nomisec WRITEUP
by Akhlak2511 · poc
https://github.com/Akhlak2511/CVE-2024-50968

This repository contains a detailed writeup describing a business logic vulnerability in itsourcecode Agri-Trading Online Shopping System 1.0. The vulnerability allows attackers to manipulate the 'quant' parameter to set the total price to zero by using a value of -0.

Classification
Writeup 90%
Attack Type
Other
Complexity
Trivial
Reliability
Reliable
Target: itsourcecode Agri-Trading Online Shopping System 1.0
Auth required
Prerequisites: Local setup of the application · User account registration and login · Interception tool like Burp Suite
devstral-2 · analyzed Feb 16, 2026 Full analysis →

References (1)

Core 1
Core References
Exploit, Third Party Advisory
https://github.com/Akhlak2511/CVE-2024-50968

Scores

CVSS v3 7.5
EPSS 0.0084
EPSS Percentile 53.1%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable yes
Technical Impact partial

Details

Status published
Products (1)
adonesevangelista/agri-trading_online_shopping_system 1.0
Published Nov 14, 2024
Tracked Since Feb 18, 2026