CVE detail
CVE-2020-21503 — CVE-2020-21503
Published 2021-10-05 · Modified 2026-06-17 · Vendor waimai_super_cms_project · Product waimai_super_cms · Source nvd
HIGH
severity
CVSS-derived band
0.0105
EPSS probability
exploitation probability, 30d
61.0%
EPSS percentile
percentile vs all CVEs
NOT LISTED
CISA KEV
known exploited catalog
Description
waimai Super Cms 20150505 has a logic flaw allowing attackers to modify a price, before form submission, by observing data in a packet capture. By setting the index.php?m=gift&a=addsave credit parameter to -1, the product is sold for free.
Remediation
No vendor-published fix data in our corpus for this CVE. Check the references below or the vendor's PSIRT / security advisories page.
References