Skip to content

Negative discount values accepted and propagated through order calculation pipeline

Moderate
mckenziearts published GHSA-5vf4-452p-jjhf Jun 22, 2026

Package

composer shopper/framework (Composer)

Affected versions

< 2.9.0

Patched versions

2.9.0

Description

Summary

The Shopper Framework discount management functionality accepts negative discount values without server-side validation.

I confirmed that negative fixed-amount discounts can be created through the administrative interface, persisted to the database, and subsequently processed by the cart/order calculation pipeline.

The application appears to assume that discount values are always positive but does not enforce this assumption during creation, storage, or calculation.

As a result, malformed discount records can influence financial calculations and produce unintended order totals.


Affected Product

Package: shopper/framework

Version Tested: 2.8.1


Vulnerability Type

  • Business Logic Vulnerability
  • Improper Input Validation (CWE-20)

Description

While reviewing the discount functionality, I discovered that the application accepts negative discount values through the administrative interface.

Example values tested:

-50.00
-99,999,999.00

The application accepted these values without validation and stored them in the database.

Example records observed in the sh_discounts table:

1 | QCZ5Y3HESM | fixed_amount | -5000
4 | TOZKAHCB4S | fixed_amount | -9999999900

This demonstrates that negative discount values are successfully persisted.


Steps to Reproduce

1. Create a Discount

Login as an administrator.

Navigate to:

/cpanel/discounts

Create a new discount with the following values:

Type: fixed_amount
Value: -99999999

Save the discount.

2. Observe Successful Creation

The discount is accepted by the application and displayed in the administration interface.

Example:

Code: TOZKAHCB4S
Amount: -$99,999,999.00

3. Verify Database Persistence

Inspect the database:

select * from sh_discounts;

Observed entry:

TOZKAHCB4S | fixed_amount | -9999999900

Technical Analysis

Discount Calculation

File:

vendor/shopper/cart/src/Discounts/DiscountCalculator.php

Observed code:

$fixedAmount = $discount->value;

The value is later processed without validation:

$fixedAmount = min($fixedAmount, $applicableSubtotal);

When a negative value is supplied:

min(-9999999900, 10000)

returns:

-9999999900

allowing the negative value to continue through the calculation pipeline.

The resulting adjustment values are inserted into the database:

CartLineAdjustment::query()->insert($adjustments);

No validation was identified to ensure that discount amounts are positive before calculations occur.


Final Total Calculation

File:

vendor/shopper/cart/src/Pipelines/Calculate.php

Observed logic:

$context->total = max(
    0,
    $context->taxInclusive
        ? $context->subtotal - $context->discountTotal
        : $context->subtotal - $context->discountTotal + $context->taxTotal
);

Because negative discount values are allowed to reach this stage, financial calculations are performed using malformed discount data.

Example:

Subtotal      = 10000
DiscountTotal = -5000

Resulting calculation:

10000 - (-5000)

Result:

15000

This demonstrates that negative discount values directly affect order total calculations.


Impact

I confirmed the following:

  • Negative discount values are accepted.
  • Negative discount values are persisted.
  • Negative discount values are processed by the discount calculation engine.
  • Negative discount values affect order total calculations.

Potential consequences include:

  • Incorrect pricing calculations.
  • Financial data integrity issues.
  • Unexpected order totals.
  • Violated assumptions within downstream pricing logic.
  • Future vulnerabilities if additional components assume discount values are always positive.

Because Shopper is a headless e-commerce administration framework and does not ship with a customer-facing storefront, I have not verified a customer-facing exploitation path.

However, malformed discount records currently propagate through pricing calculations without validation.


Recommendation

Implement server-side validation enforcing positive discount values before persistence and before entering the calculation pipeline.

Suggested validation:

Fixed Amount Discounts

value > 0

Percentage Discounts

0 < value <= 100

Additionally, existing discount records should be validated before calculation to prevent malformed data from influencing pricing logic.


Environment

Shopper Framework 2.8.1
Laravel 12.61.1
PHP 8.4.16
SQLite

Severity

Moderate

CVSS overall score

This score calculates overall vulnerability severity from 0 to 10 and is based on the Common Vulnerability Scoring System (CVSS).
/ 10

CVSS v3 base metrics

Attack vector
Network
Attack complexity
Low
Privileges required
Low
User interaction
None
Scope
Unchanged
Confidentiality
None
Integrity
High
Availability
None

CVSS v3 base metrics

Attack vector: More severe the more the remote (logically and physically) an attacker can be in order to exploit the vulnerability.
Attack complexity: More severe for the least complex attacks.
Privileges required: More severe if no privileges are required.
User interaction: More severe when no user interaction is required.
Scope: More severe when a scope change occurs, e.g. one vulnerable component impacts resources in components beyond its security scope.
Confidentiality: More severe when loss of data confidentiality is highest, measuring the level of data access available to an unauthorized user.
Integrity: More severe when loss of data integrity is the highest, measuring the consequence of data modification possible by an unauthorized user.
Availability: More severe when the loss of impacted component availability is highest.
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N

CVE ID

CVE-2026-56831

Weaknesses

Improper Input Validation

The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly. Learn more on MITRE.

Credits