CVE-2024-6128
Spa-cart
CVE-2024-6128: A problematic vulnerability exists in spa-cartcms 1.9.0.6, affecting the Checkout Page. This behavioral workflow enforcement can be triggered remotely by manipulating the quantity argument with a negative value like -10. Although the CVSS score is 5.3, indicating a medium severity, the SOCRadar Vulnerability Risk Score (SVRS) of 52 suggests a moderate risk level. This vulnerability, identified as VDB-268895, allows for potential manipulation of the checkout process. The exploit is public, meaning attacks are possible and readily available. While not critical based on SVRS, organizations using spa-cartcms should address this vulnerability to prevent abuse of the shopping cart functionality. This could lead to unexpected order processing and potential disruption of e-commerce operations.
Description
CVE-2024-6128 is a problematic vulnerability in spa-cartcms 1.9.0.6 that allows remote attackers to enforce behavioral workflow by manipulating the quantity argument with the input -10 in the Checkout Page component. The vulnerability has been publicly disclosed and may be actively exploited.
Key Insights
- SVRS Score: 52, indicating a moderate risk.
- Exploit Status: Active exploits have been published.
- CISA Warning: The Cybersecurity and Infrastructure Security Agency (CISA) has not issued a warning for this vulnerability.
- In the Wild: The vulnerability is not known to be actively exploited in the wild.
Mitigation Strategies
- Update spa-cartcms to version 1.9.0.7 or later.
- Implement input validation to prevent the manipulation of the quantity argument.
- Monitor for suspicious activity and take appropriate action if necessary.
- Consider using a web application firewall (WAF) to block malicious requests.
Additional Information
If users have additional queries regarding this incident, they can use the 'Ask to Analyst' feature, contact SOCRadar directly, or open a support ticket for more information if necessary.
Indicators of Compromise
Exploits
News
Social Media
Affected Software
References
CWE Details
CVE Radar
Real-time CVE Intelligence & Vulnerability Management Platform
CVE Radar provides comprehensive vulnerability intelligence by monitoring CVE databases, security advisories, and threat feeds. Get instant updates on new vulnerabilities, exploit details, and mitigation strategies specific to your assets.