CVE-2018-8761

protectedappsmembercontrollershopcarController.php in Yxcms building system (compatible cell phone) v1.4.7 has a logic flaw allowing attackers to modify a price, before form submission, by observing data in a packet capture.
References
Configurations

Configuration 1

cpe:2.3:a:yxcms:yxcms:1.4.7:*:*:*:*:*:*:*

Information

Published : 2018-03-19 02:29

Updated : 2019-10-03 12:03


NVD link : CVE-2018-8761

Mitre link : CVE-2018-8761

Products Affected
No products.