PT-2024-37405 · Unknown · Spa-Cartcms

·

CVE-2024-6129

·

Published

2024-06-18

·

Updated

2024-09-20

CVSS v3.1

3.7

Low

VectorAV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions: spa-cartcms version 1.9.0.6
Description: A problematic issue was found in the Username Handler component, specifically in the /login file, where manipulating the email argument leads to observable behavioral discrepancy. This issue can be exploited remotely, with a rather high complexity of attack and difficult exploitability. The exploit has been disclosed to the public.
Recommendations: For version 1.9.0.6, consider restricting access to the /login endpoint or the email argument to minimize the risk of exploitation until a fix is available. As a temporary workaround, consider disabling the unknown function of the Username Handler component that handles the email argument.

Exploit

Fix

Side Channel Attack

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2024-6129

Affected Products

Spa-Cartcms