Sceawere
Vulnerability Detail
CVE-2026-103351UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
Improper Quantity Validation in Taxi Booking Manager
Vulnerability Metadata
- Severity
- Medium
- Score / CVSS
- 5.3
- Creation Date
- 10h ago
- Vendor
- Magepeople inc.
- Product
- Taxi Booking Manager for WooCommerce
- Attack Type
- Improper Validation of Specified Quantity in Input
- Vector String
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
- Attack Complexity
- LOW
Narrative and Response
Description
Improper Validation of Specified Quantity in Input vulnerability in Magepeople inc. Taxi Booking Manager for WooCommerce ecab-taxi-booking-manager allows Input Data Manipulation.This issue affects Taxi Booking Manager for WooCommerce: from n/a through 2.1.1.
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "5.3",
"pubDate": "2026-10-05T09:17:06.693Z",
"pubdate": "2026-10-05T09:17:06.693Z",
"executiveSummary": "The Taxi Booking Manager for WooCommerce plugin is susceptible to an Improper Validation of Specified Quantity vulnerability.\nThis vulnerability allows an attacker to manipulate input data related to booking quantities, which can lead to unauthorized changes in order parameters.\nThe issue affects versions from n/a through 2.1.1 of the Taxi Booking Manager for WooCommerce product.\nThe risk implication is primarily financial and operational, as malicious actors can tamper with the quantity of services requested, potentially leading to incorrect billing or inventory exhaustion.\nExploitation requires the attacker to interact with the booking request parameters, typically performed via HTTP requests during the checkout or booking process.\nNo specific authentication is necessarily required to perform the manipulation if the vulnerable input field is exposed on the public-facing booking interface.\nSuccessful exploitation allows an attacker to bypass business logic controls enforced by the application's quantity verification mechanisms.",
"technicalDetails": "The vulnerability originates from a failure to adequately sanitize or validate the numerical input fields provided by users during the taxi booking process within the Taxi Booking Manager for WooCommerce plugin.\nSpecifically, the application fails to perform server-side verification of the 'quantity' parameter before processing the booking logic, allowing an attacker to submit arbitrary integer values that deviate from the expected or allowed range.\nThe root cause is an insecure implementation of business logic where the plugin assumes the client-side quantity constraints are sufficient. When the application receives a request, it neglects to cross-reference the submitted quantity against the defined inventory limits or service constraints, thereby trusting user-supplied data implicitly.\nThe attack flow proceeds as follows: 1. An attacker initiates a booking request for a service managed by the Taxi Booking Manager. 2. During the transmission of the booking request (often via a POST request containing WooCommerce cart or checkout data), the attacker intercepts the traffic using a proxy tool such as Burp Suite. 3. The attacker modifies the quantity parameter value to a non-permitted, negative, or extremely large number. 4. The server-side component of the plugin processes the manipulated request, updating the booking object or cart session with the malicious value. 5. This results in an inconsistent state, allowing the attacker to influence the total cost, availability, or other service-specific metrics.\nThis vulnerability is categorized as an Input Data Manipulation issue, specifically related to the lack of strict type and range checking. Since the plugin operates within the WordPress/WooCommerce environment, it utilizes the standard hook system to process data; the flaw lies in the function responsible for receiving and validating the booking parameters before finalizing the transaction.\nImpacts include the potential for financial loss due to incorrect pricing calculations based on manipulated quantities, exhaustion of resources if booking limits are ignored, and potential bypasses of service availability checks. Because the vulnerability exists in the core booking flow, it is exposed to any user capable of reaching the booking checkout page, irrespective of their account status, assuming the booking flow is publicly accessible.\nThe lack of integrity checks on user-provided parameters creates a vector for manipulation that persists until the order is finalized or manual intervention occurs by the site administrator."
}