Show plain JSON{"id": "CVE-2018-8761", "metrics": {"cvssMetricV2": [{"type": "Primary", "source": "nvd@nist.gov", "cvssData": {"version": "2.0", "baseScore": 5.0, "accessVector": "NETWORK", "vectorString": "AV:N/AC:L/Au:N/C:N/I:P/A:N", "authentication": "NONE", "integrityImpact": "PARTIAL", "accessComplexity": "LOW", "availabilityImpact": "NONE", "confidentialityImpact": "NONE"}, "acInsufInfo": false, "impactScore": 2.9, "baseSeverity": "MEDIUM", "obtainAllPrivilege": false, "exploitabilityScore": 10.0, "obtainUserPrivilege": false, "obtainOtherPrivilege": false, "userInteractionRequired": false}], "cvssMetricV30": [{"type": "Primary", "source": "nvd@nist.gov", "cvssData": {"scope": "UNCHANGED", "version": "3.0", "baseScore": 7.5, "attackVector": "NETWORK", "baseSeverity": "HIGH", "vectorString": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N", "integrityImpact": "HIGH", "userInteraction": "NONE", "attackComplexity": "LOW", "availabilityImpact": "NONE", "privilegesRequired": "NONE", "confidentialityImpact": "NONE"}, "impactScore": 3.6, "exploitabilityScore": 3.9}]}, "published": "2018-03-19T14:29:00.410", "references": [{"url": "https://github.com/QQ704568679/-/blob/master/YXcms%20TheCode%20audit", "tags": ["Third Party Advisory"], "source": "cve@mitre.org"}, {"url": "https://github.com/QQ704568679/-/blob/master/YXcms%20TheCode%20audit", "tags": ["Third Party Advisory"], "source": "af854a3a-2127-422b-91ae-364da2661108"}], "vulnStatus": "Modified", "weaknesses": [{"type": "Primary", "source": "nvd@nist.gov", "description": [{"lang": "en", "value": "NVD-CWE-noinfo"}]}], "descriptions": [{"lang": "en", "value": "protected\\apps\\member\\controller\\shopcarController.php in Yxcms building system (compatible cell phone) v1.4.7 has a logic flaw allowing attackers to modify a price, before form submission, by observing data in a packet capture."}, {"lang": "es", "value": "protected\\apps\\member\\controller\\shopcarController.php en el sistema de construcci\u00f3n de Yxcms (tel\u00e9fonos compatibles) v1.4.7 tiene un error de l\u00f3gica que permite que atacantes modifiquen un precio, antes de enviar el formulario, observando los datos en una captura de paquete."}], "lastModified": "2024-11-21T04:14:15.780", "configurations": [{"nodes": [{"negate": false, "cpeMatch": [{"criteria": "cpe:2.3:a:yxcms:yxcms:1.4.7:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "194FA8EF-7133-43E1-AFBE-20CE6BFC5A60"}], "operator": "OR"}]}], "sourceIdentifier": "cve@mitre.org"}