Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
Smartstore Gift Voucher confirm race condition
Vulnerability Description
A vulnerability has been found in Smartstore up to 6.2.0. The affected element is an unknown function of the file /checkout/confirm/ of the component Gift Voucher Handler. The manipulation leads to race condition. The attack may be initiated remotely. The attack's complexity is rated as high. The exploitability is described as difficult. The vendor was contacted early about this disclosure but did not respond in any way.
CVSS Information
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:L/A:N
Vulnerability Type
使用共享资源的并发执行不恰当同步问题(竞争条件)
Vulnerability Title
Smartstore 竞争条件问题漏洞
Vulnerability Description
Smartstore是Smartstore AG开源的一个电子商务平台。。 Smartstore 6.2.0及之前版本存在竞争条件问题漏洞,该漏洞源于组件Gift Voucher Handler中文件/checkout/confirm存在竞争条件,可能导致远程攻击。
CVSS Information
N/A
Vulnerability Type
N/A