An issue was discovered in the NAB Transact extension 2.1.0 for the WooCommerce plugin for WordPress. An online payment system bypass allows orders to be marked as fully paid by assigning an arbitrary bank transaction ID during the payment-details entry step.
References
Link | Resource |
---|---|
http://packetstormsecurity.com/files/158931/WordPress-NAB-Transact-WooCommerce-2.1.0-Payment-Bypass.html | Third Party Advisory |
http://seclists.org/fulldisclosure/2020/Aug/13 | Exploit Mailing List Third Party Advisory |
http://seclists.org/fulldisclosure/2020/Aug/13 | Exploit Mailing List Third Party Advisory |
https://www.themissinglink.com.au/security-advisories-cve-2020-11497 | Exploit Third Party Advisory |
http://packetstormsecurity.com/files/158931/WordPress-NAB-Transact-WooCommerce-2.1.0-Payment-Bypass.html | Third Party Advisory |
http://seclists.org/fulldisclosure/2020/Aug/13 | Exploit Mailing List Third Party Advisory |
http://seclists.org/fulldisclosure/2020/Aug/13 | Exploit Mailing List Third Party Advisory |
https://www.themissinglink.com.au/security-advisories-cve-2020-11497 | Exploit Third Party Advisory |
Configurations
History
21 Nov 2024, 04:58
Type | Values Removed | Values Added |
---|---|---|
References | () http://packetstormsecurity.com/files/158931/WordPress-NAB-Transact-WooCommerce-2.1.0-Payment-Bypass.html - Third Party Advisory | |
References | () http://seclists.org/fulldisclosure/2020/Aug/13 - Exploit, Mailing List, Third Party Advisory | |
References | () https://www.themissinglink.com.au/security-advisories-cve-2020-11497 - Exploit, Third Party Advisory |
Information
Published : 2020-08-26 19:15
Updated : 2024-11-21 04:58
NVD link : CVE-2020-11497
Mitre link : CVE-2020-11497
CVE.ORG link : CVE-2020-11497
JSON object : View
Products Affected
woocommerce
- nab_transact
CWE
CWE-354
Improper Validation of Integrity Check Value