- Ubercart 1.x.x versions prior to 1.x-1.0.4-beta
The Ubercart module provides a shopping cart and e-commerce features for Backdrop CMS.
The taxes module doesn't sufficiently protect the tax rate cloning feature. A malicious user could trick a store administrator into duplicating an existing tax rate by getting them to visit a specially-crafted URL.
Upgrade your site to the most recent version of Ubercart. Download available on the Ubercart 1.x-1.0.4-beta release page. See the update instructions, if needed.
- Dave Long
- Ayesh Karunaratne
- Tim Rohaly
- klonos of the Backdrop Contrib Security Team
- Michael Hess of the Drupal Security Team
- Jen Lampton of the Backdrop Contrib Security Team