PT-2022-20447 · Unknown · Solidus Backend

Published

2022-06-01

·

Updated

2022-06-08

·

CVE-2022-31000

CVSS v2.0

4.3

Medium

VectorAV:N/AC:M/Au:N/C:N/I:P/A:N
Name of the Vulnerable Software and Affected Versions solidus backend versions prior to 3.1.6 solidus backend versions prior to 3.0.6 solidus backend versions prior to 2.11.16
Description The vulnerability is a cross-site request forgery (CSRF) issue that allows attackers to change the state of an order's adjustments if they hold its number. This execution occurs on a store administrator's computer.
Recommendations For solidus backend versions prior to 3.1.6, upgrade to version 3.1.6 to receive the patch. For solidus backend versions prior to 3.0.6, upgrade to version 3.0.6 to receive the patch. For solidus backend versions prior to 2.11.16, upgrade to version 2.11.16 to receive the patch. As a temporary workaround, consider restricting access to the /admin/orders/{order number}/adjustments/unfinalize and /admin/orders/{order number}/adjustments/finalize API endpoints until a patch is available.

Exploit

Fix

CSRF

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2022-31000
GHSA-8639-QX56-R428

Affected Products

Solidus Backend