Metrics
Affected Vendors & Products
Fri, 12 Sep 2025 08:15:00 +0000
| Type | Values Removed | Values Added | 
|---|---|---|
| First Time appeared | Grandnode Grandnode grandnode | |
| Vendors & Products | Grandnode Grandnode grandnode | 
Thu, 11 Sep 2025 16:15:00 +0000
| Type | Values Removed | Values Added | 
|---|---|---|
| Metrics | ssvc 
 | 
Wed, 10 Sep 2025 21:15:00 +0000
| Type | Values Removed | Values Added | 
|---|---|---|
| Description | A vulnerability was detected in GrandNode up to 2.3.0. The impacted element is an unknown function of the file /checkout/ConfirmOrder/ of the component Voucher Handler. The manipulation of the argument giftvouchercouponcode results in race condition. The attack may be launched remotely. The attack requires a high level of complexity. The exploitability is regarded as difficult. The vendor was contacted early about this disclosure but did not respond in any way. | |
| Title | GrandNode Voucher ConfirmOrder race condition | |
| Weaknesses | CWE-362 | |
| References |  | |
| Metrics | cvssV2_0 
 
 
 
 | 
 MITRE
                        MITRE
                    Status: PUBLISHED
Assigner: VulDB
Published: 2025-09-10T21:02:05.844Z
Updated: 2025-09-11T15:33:10.813Z
Reserved: 2025-09-10T10:48:01.840Z
Link: CVE-2025-10216
 Vulnrichment
                        Vulnrichment
                    Updated: 2025-09-11T15:32:47.993Z
 NVD
                        NVD
                    Status : Awaiting Analysis
Published: 2025-09-10T21:15:34.533
Modified: 2025-09-11T17:14:10.147
Link: CVE-2025-10216
 Redhat
                        Redhat
                    No data.