Nebulab

Solidus

4 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
Exploit
  • EPSS 0.17%
  • Veröffentlicht 01.06.2022 18:15:07
  • Zuletzt bearbeitet 21.11.2024 07:03:41

solidus_backend is the admin interface for the Solidus e-commerce framework. Versions prior to 3.1.6, 3.0.6, and 2.11.16 contain a cross-site request forgery (CSRF) vulnerability. The vulnerability allows attackers to change the state of an order's a...

Exploit
  • EPSS 0.13%
  • Veröffentlicht 20.12.2021 22:15:07
  • Zuletzt bearbeitet 21.11.2024 06:29:55

`solidus_frontend` is the cart and storefront for the Solidus e-commerce project. Versions of `solidus_frontend` prior to 3.1.5, 3.0.5, and 2.11.14 contain a cross-site request forgery (CSRF) vulnerability that allows a malicious site to add an item ...

Exploit
  • EPSS 0.12%
  • Veröffentlicht 07.12.2021 18:15:07
  • Zuletzt bearbeitet 21.11.2024 06:29:49

Solidus is a free, open-source ecommerce platform built on Rails. Versions of Solidus prior to 3.1.4, 3.0.4, and 2.11.13 have a denial of service vulnerability that could be exploited during a guest checkout. The regular expression used to validate a...

Exploit
  • EPSS 0.21%
  • Veröffentlicht 04.08.2020 23:15:10
  • Zuletzt bearbeitet 21.11.2024 05:04:49

In solidus before versions 2.8.6, 2.9.6, and 2.10.2, there is an bility to change order address without triggering address validations. This vulnerability allows a malicious customer to craft request data with parameters that allow changing the addre...