CVE-2024-6128
MEDIUMDescription
A vulnerability, which was classified as problematic, has been found in spa-cartcms 1.9.0.6. This issue affects some unknown processing of the file /checkout of the component Checkout Page. The manipulation of the argument quantity with the input -10 leads to enforcement of behavioral workflow. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-268895.
Is your site exposed to CVE-2024-6128?
Run a free security scan — no signup, results in seconds.
CVSS v3.1 Score
Weakness Type (CWE)
Affected Products
| Vendor | Product |
|---|---|
| spa-cart | spa-cartcms |
References
Exploits
Frequently Asked Questions
What is CVE-2024-6128? +
How severe is CVE-2024-6128? +
What products are affected by CVE-2024-6128? +
How do I check if I'm vulnerable to CVE-2024-6128? +
Related Vulnerabilities
User Enumeration and Data Integrity in Barcode functionality in OpenText Content Management versions 24.3-25.1on Windows and Linux allows a malicous …
Fides is an open-source privacy engineering platform. From 2.75.0 to before 2.83.2, Fides deployments that enable both subject identity verification …
Unexpected Status Code or Return Value vulnerability in ninenines gun (gun_http module) allows a malicious HTTP server to force the …
Our payment integration with GiroCheckout did not properly validate payment status responses. An attacker could use a successful payment status …
Klever-Go is the Go implementation of the Klever blockchain protocol. Prior to 1.7.19, processPercentageRoyaltiesTransfer in core/kapp/accounts/accounts.go calls SubFromBalance after the …
A pop-up logic flaw in a certain feature of Kids Mode allows users to bypass password verification and use Quick …