PT-2025-38677 · Unknown · Smartstore
Kkc73
·
Published
2025-09-22
·
Updated
2025-09-22
·
CVE-2025-10778
CVSS v3.1
3.1
Low
| Vector | AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
Smartstore versions prior to 6.2.1
Description
A race condition exists in the Gift Voucher Handler component of Smartstore. The issue is located in an unknown function within the
/checkout/confirm/ file. The attack can be initiated remotely and is considered difficult to exploit, with high complexity. The vendor was contacted regarding this issue but did not respond.Recommendations
Update Smartstore to version 6.2.1 or later.
Fix
Race Condition
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Smartstore