Mass Assignment Vulnerability in Spree Auth Devise for Spree E-commerce Platform
CVE-2013-2506
Currently unrated
What is CVE-2013-2506?
The Spree Auth Devise for the Spree e-commerce platform contains a vulnerability in the user.rb model, where insufficient mass assignment protection allows authenticated users to manipulate their own roles. This issue affects versions of Spree 1.1.x prior to 1.1.6, as well as 1.2.x and 1.3.x versions. If exploited, it can enable unauthorized escalation of privileges, compromising the integrity of user management on the platform.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
