Review reviewHigh
CVE-2024-46307
sparkshop
A loop hole in the payment logic of Sparkshop v1.16 allows attackers to arbitrarily modify the number of products.
- CVSS
- 7.5
- EPSS
- 0.46% 37.5% percentile
- CISA KEV
- Not listed
- Published
- 2024.10.10
A loop hole in the payment logic of Sparkshop v1.16 allows attackers to arbitrarily modify the number of products.
The CVSS severity warrants an early asset and exposure review.
A loop hole in the payment logic of Sparkshop v1.16 allows attackers to arbitrarily modify the number of products.
Confirm exposure before applying a vendor-supported change.
Confirm that sparkshop and an affected version are present.
Combine exploitation signals with asset exposure and business criticality.
Follow the vendor advisory or supported update path and preserve rollback options.
Recheck the version, service health, access paths, and relevant logs.