Business Logic Errors in yetiforcecompany/yetiforcecrm
Dec 10th 2021
The application is vulnerable to Business Logic error through negative product amount.
Proof of Concept
Step 1: Login into the application https://gitstable.yetiforce.com/index.php
Step 2: Navigate to Database -> Product -> Edit any product.
Step 3: Now enter a negative amount in Unit Price field and click on save. Here a product is added with a negative amount.