An issue was discovered in Optimizely Configured Commerce before 5.2.2408. A medium-severity issue concerning business logic exists in the Commerce B2B application, which allows storefront visitors to purchase discontinued products in specific scenarios where requests are altered before reaching the server.
References
Configurations
No configuration.
History
06 Jan 2025, 17:15
Type | Values Removed | Values Added |
---|---|---|
CVSS |
v2 : v3 : |
v2 : unknown
v3 : 7.5 |
04 Jan 2025, 02:15
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2025-01-04 02:15
Updated : 2025-01-06 17:15
NVD link : CVE-2025-22384
Mitre link : CVE-2025-22384
CVE.ORG link : CVE-2025-22384
JSON object : View
Products Affected
No product.
CWE
CWE-472
External Control of Assumed-Immutable Web Parameter