CVE-2021-4031

Severity CVSS v4.0:
Pending analysis
Type:
CWE-345 Insufficient Verification of Data Authenticity
Publication date:
18/03/2022
Last modified:
29/03/2022

Description

Syltek application before its 10.22.00 version, does not correctly check that a product ID has a valid payment associated to it. This could allow an attacker to forge a request and bypass the payment system by marking items as payed without any verification.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:syltek:syltek:*:*:*:*:*:*:*:* 10.22.00 (excluding)