Lucene search

K
huntrLaladeeED3ED4CE-3968-433C-A350-351C8F8B60DB
HistoryJan 09, 2022 - 4:08 p.m.

Business Logic Errors in dolibarr/dolibarr

2022-01-0916:08:41
laladee
www.huntr.dev
7
business logic errors
input validation
security flaws
bug bounty
pricing issues

EPSS

0.001

Percentile

24.8%

Description

The application does not check the input of price number lead to Business Logic error through negative price amount.

Proof of Concept

  1. Go to Product and Services area htdocs/product/index.php

  2. Create a new or edit an item, insert a negative amount into Selling price field.

Also in Billing and payment area andDonations area and maybe more

Impact

Business logic can have security flaws that allow a user to do something that isn’t allowed by the business, in business logic can be devastating to an entire application. They can be difficult to find automatically, since they typically involve legitimate use of the application’s functionality.

EPSS

0.001

Percentile

24.8%

Related for ED3ED4CE-3968-433C-A350-351C8F8B60DB