viewcart in Midicart accepts negative numbers in the Qty (quantity) field, which allows remote attackers to obtain a smaller total price for a shopping cart.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Midicart_php_shopping_cart | Midicart_software | * | * |