Low severity3.5NVD Advisory· Published Apr 16, 2025· Updated Jun 17, 2026
CVE-2024-58248
CVE-2024-58248
Description
nopCommerce through 4.90.1 does not offer locking for order placement. Thus there is a race condition with duplicate redeeming of gift cards.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
3cpe:2.3:a:nopcommerce:nopcommerce:*:*:*:*:*:*:*:*+ 2 more
- cpe:2.3:a:nopcommerce:nopcommerce:*:*:*:*:*:*:*:*range: <4.80.0
- (no CPE)range: <=4.90.1
- (no CPE)range: 0
Patches
Vulnerability mechanics
References
3- github.com/nopSolutions/nopCommerce/issues/7325nvdIssue TrackingPatchVendor Advisory
- github.com/Fabian-For/Vulnerability-Research/blob/main/CVE-2024-58248/README.mdnvdExploitThird Party Advisory
- www.nopcommerce.com/en/release-notesnvdRelease Notes
News mentions
0No linked articles in our index yet.