An issue was discovered in Optimizely Configured Commerce before 5.2.2408. A medium-severity issue concerning business logic exists in the Commerce B2B application, which allows storefront visitors to purchase discontinued products in specific scenarios where requests are altered before reaching the server.
Metrics
Affected Vendors & Products
References
History
Mon, 06 Jan 2025 17:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
cvssV3_1
|
Sat, 04 Jan 2025 02:45:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | An issue was discovered in Optimizely Configured Commerce before 5.2.2408. A medium-severity issue concerning business logic exists in the Commerce B2B application, which allows storefront visitors to purchase discontinued products in specific scenarios where requests are altered before reaching the server. | |
Weaknesses | CWE-472 | |
References |
|

Status: PUBLISHED
Assigner: mitre
Published: 2025-01-04T00:00:00
Updated: 2025-01-06T17:02:30.455Z
Reserved: 2025-01-04T00:00:00
Link: CVE-2025-22384

Updated: 2025-01-06T17:02:24.462Z

Status : Awaiting Analysis
Published: 2025-01-04T02:15:06.937
Modified: 2025-01-06T17:15:47.820
Link: CVE-2025-22384

No data.