CVE-2024-30527 Vulnerability Details
/
/
/
CVE-2024-30527 Metadata Quick Info
CVE Published: 17/05/2024 |
CVE Updated: 02/08/2024 |
CVE Year: 2024
Source: Patchstack |
Vendor: Tips and Tricks HQ |
Product: WP Express Checkout (Accept PayPal Payments)
Status : PUBLISHED
CVE-2024-30527 Description
Improper Validation of Specified Quantity in Input vulnerability in Tips and Tricks HQ WP Express Checkout (Accept PayPal Payments) allows Manipulating Hidden Fields.This issue affects WP Express Checkout (Accept PayPal Payments): from n/a through 2.3.7.
Metrics
CVSS Version: 3.1 |
Base Score: 7.5 HIGH
Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
l➤ Exploitability Metrics:
Attack Vector (AV)* NETWORK
Attack Complexity (AC)* LOW
Privileges Required (PR)* NONE
User Interaction (UI)* NONE
Scope (S)* UNCHANGED
l➤ Impact Metrics:
Confidentiality Impact (C)* NONE
Integrity Impact (I)* HIGH
Availability Impact (A)* NONE
Weakness Enumeration (CWE)
CWE-ID: CWE-1284
CWE Name: CWE-1284 Improper Validation of Specified Quantity in Input
Source: Tips and Tricks HQ
Common Attack Pattern Enumeration and Classification (CAPEC)
CAPEC-ID: CAPEC-162
CAPEC Description: CAPEC-162 Manipulating Hidden Fields
Source: NVD (National Vulnerability Database).