PT-2025-33088 · Unknown · Spree Commerce
Published
2025-08-13
·
Updated
2025-08-18
·
CVE-2011-10019
CVSS v3.1
9.8
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions:
Spreecommerce versions prior to 0.60.2
Description:
Spreecommerce versions prior to 0.60.2 contain a remote command execution issue in the search functionality. The application does not properly sanitize input passed via the
search[send][] parameter, which is dynamically invoked using Ruby’s send method. This allows attackers to execute arbitrary shell commands on the server without authentication.Recommendations:
Update to Spreecommerce version 0.60.2 or later.
Exploit
Fix
Prototype Pollution
Code Injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Spree Commerce