Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2024-51975 | A race condition vulnerability in SimplCommerce at commit 230310c8d7a0408569b292c5a805c459d47a1d8f allows attackers to bypass inventory restrictions by simultaneously submitting purchase requests from multiple accounts for the same product. This can lead to overselling when stock is limited, as the system fails to accurately track inventory under high concurrency, resulting in potential loss and unfulfilled orders. |
Sat, 28 Dec 2024 19:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-362 | |
| Metrics |
cvssV3_1
|
Fri, 27 Dec 2024 19:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A race condition vulnerability in SimplCommerce at commit 230310c8d7a0408569b292c5a805c459d47a1d8f allows attackers to bypass inventory restrictions by simultaneously submitting purchase requests from multiple accounts for the same product. This can lead to overselling when stock is limited, as the system fails to accurately track inventory under high concurrency, resulting in potential loss and unfulfilled orders. | |
| References |
|
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2024-12-28T18:22:23.419Z
Reserved: 2024-11-20T00:00:00.000Z
Link: CVE-2024-53476
Updated: 2024-12-28T18:22:17.849Z
Status : Deferred
Published: 2024-12-27T19:15:09.103
Modified: 2026-04-15T00:35:42.020
Link: CVE-2024-53476
No data.
OpenCVE Enrichment
Updated: 2025-07-12T22:23:30Z
EUVD