Remote Code Execution Vulnerability in Spree Commerce by Spree Solutions
CVE-2013-1656

Currently unrated

Key Information:

Status
Vendor
CVE Published:
8 March 2013

What is CVE-2013-1656?

The vulnerability in Spree Commerce versions 1.0.x through 1.3.2 allows authenticated administrators to exploit unsafe use of the constantize function in various parameters. This can lead to the instantiation of arbitrary Ruby objects and execution of arbitrary commands, posing a significant security risk. Attackers can manipulate parameters such as payment_method, promotion_action, promotion_rule, and calculator_type to execute malicious code, potentially compromising the integrity of the application.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.

Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.