PT-2025-33088 · Unknown · Spree Commerce

Published

2025-08-13

·

Updated

2025-08-18

·

CVE-2011-10019

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions: Spreecommerce versions prior to 0.60.2
Description: Spreecommerce versions prior to 0.60.2 contain a remote command execution issue in the search functionality. The application does not properly sanitize input passed via the search[send][] parameter, which is dynamically invoked using Ruby’s send method. This allows attackers to execute arbitrary shell commands on the server without authentication.
Recommendations: Update to Spreecommerce version 0.60.2 or later.

Exploit

Fix

Prototype Pollution

Code Injection

Weakness Enumeration

Related Identifiers

CVE-2011-10019
GHSA-97VM-C39P-JR86

Affected Products

Spree Commerce