An issue was discovered in the NAB Transact extension 2.1.0 for the WooCommerce plugin for WordPress. An online payment system bypass allows orders to be marked as fully paid by assigning an arbitrary bank transaction ID during the payment-details entry step.
References
Link | Resource |
---|---|
https://www.themissinglink.com.au/security-advisories-cve-2020-11497 | Exploit Third Party Advisory |
http://seclists.org/fulldisclosure/2020/Aug/13 | Exploit Mailing List Third Party Advisory |
http://packetstormsecurity.com/files/158931/WordPress-NAB-Transact-WooCommerce-2.1.0-Payment-Bypass.html | Third Party Advisory |
Configurations
Information
Published : 2020-08-26 12:15
Updated : 2020-09-01 07:28
NVD link : CVE-2020-11497
Mitre link : CVE-2020-11497
JSON object : View
CWE
CWE-354
Improper Validation of Integrity Check Value
Products Affected
woocommerce
- nab_transact