CVE-2020-21503 describes a logic flaw in waimai Super Cms 20150505 that allows an attacker to manipulate product prices. By intercepting and modifying the "credit" parameter to -1 during form submission, an attacker can effectively purchase products for free. This vulnerability has a CVSS score of 7.5 (HIGH), indicating a network-based attack with low complexity and high integrity impact, but no confidentiality or availability impact. While no public exploits, Metasploit modules, or Nuclei templates are available, and there's no evidence of active exploitation or significant community discussion, the potential for unauthorized free purchases makes it a notable concern for affected systems.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
20150505CPE matchmatch criteria | cpe:2.3:a:waimai_super_cms_project:waimai_super_cms:20150505:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.