CVE-2014-4962
Severity CVSS v4.0: 
            Pending analysis
                                                    Type: 
          
                          CWE-189
                        Numeric Errors
          
        Publication date: 
                          15/07/2014
                  Last modified: 
                          12/04/2025
                  Description
Shopizer 1.1.5 and earlier allows remote attackers to reduce the total cost of their shopping cart via a negative number in the productQuantity parameter, which causes the price of the item to be subtracted from the total cost.
              Impact
Base Score 2.0
          6.40
        Severity 2.0
          MEDIUM
        Vulnerable products and versions
| CPE | From | Up to | 
|---|---|---|
| cpe:2.3:a:shopizer:shopizer:*:*:*:*:*:*:*:* | 1.1.5 (including) | 
To consult the complete list of CPE names with products and versions, see this page



