CVE Radar Logo
CVERadar
CVE Radar Logo
CVERadar

CVE-2024-6128

High Severity
Spa-cart
SVRS
52/100

CVSSv3
5.3/10

EPSS
0.00082/1

CVE-2024-6128: A problematic vulnerability exists in spa-cartcms 1.9.0.6, affecting the Checkout Page. This behavioral workflow enforcement can be triggered remotely by manipulating the quantity argument with a negative value like -10. Although the CVSS score is 5.3, indicating a medium severity, the SOCRadar Vulnerability Risk Score (SVRS) of 52 suggests a moderate risk level. This vulnerability, identified as VDB-268895, allows for potential manipulation of the checkout process. The exploit is public, meaning attacks are possible and readily available. While not critical based on SVRS, organizations using spa-cartcms should address this vulnerability to prevent abuse of the shopping cart functionality. This could lead to unexpected order processing and potential disruption of e-commerce operations.

In The Wild
CVSS:3.1
AV:N
AC:L
PR:N
UI:N
S:U
C:L
I:N
A:N
2024-06-18

2024-09-20
Eye Icon
SOCRadar
AI Insight

Description

CVE-2024-6128 is a problematic vulnerability in spa-cartcms 1.9.0.6 that allows remote attackers to enforce behavioral workflow by manipulating the quantity argument with the input -10 in the Checkout Page component. The vulnerability has been publicly disclosed and may be actively exploited.

Key Insights

  • SVRS Score: 52, indicating a moderate risk.
  • Exploit Status: Active exploits have been published.
  • CISA Warning: The Cybersecurity and Infrastructure Security Agency (CISA) has not issued a warning for this vulnerability.
  • In the Wild: The vulnerability is not known to be actively exploited in the wild.

Mitigation Strategies

  • Update spa-cartcms to version 1.9.0.7 or later.
  • Implement input validation to prevent the manipulation of the quantity argument.
  • Monitor for suspicious activity and take appropriate action if necessary.
  • Consider using a web application firewall (WAF) to block malicious requests.

Additional Information

If users have additional queries regarding this incident, they can use the 'Ask to Analyst' feature, contact SOCRadar directly, or open a support ticket for more information if necessary.

Indicators of Compromise

No IOCs found for this CVE

Exploits

No exploits found for this CVE

Enhance Your CVE Management with SOCRadar Vulnerability Intelligence
Get comprehensive CVE details, real-time notifications, and proactive threat management all in one platform.
CVE Details
Access comprehensive CVE information instantly
Real-time Tracking
Subscribe to CVEs and get instant updates
Exploit Analysis
Monitor related APT groups and threats
IOC Tracking
Analyze and track CVE-related IOCs

News

CVE-2024-6128 | spa-cartcms 1.9.0.6 Checkout Page /checkout quantity behavioral workflow
vuldb.com2024-06-18
CVE-2024-6128 | spa-cartcms 1.9.0.6 Checkout Page /checkout quantity behavioral workflow | A vulnerability, which was classified as problematic, has been found in spa-cartcms 1.9.0.6. This issue affects some unknown processing of the file /checkout of the component Checkout Page. The manipulation of the argument quantity with the input -10 leads to enforcement of behavioral
cve-2024-6128
ipv4s
domains
urls

Social Media

CVE-2024-6128 A vulnerability, which was classified as problematic, has been found in spa-cartcms 1.9.0.6. This issue affects some unknown processing of the file /checkout of the com… https://t.co/geVS0rrYeW
0
0
0

Affected Software

Configuration 1
TypeVendorProduct
AppSpa-cartspa-cartcms

References

ReferenceLink
[email protected]https://msecureltd.blogspot.com/2024/04/friday-fun-pentest-series-5-spa.html
[email protected]https://seclists.org/fulldisclosure/2024/Jun/6
[email protected]https://vuldb.com/?ctiid.268895
[email protected]https://vuldb.com/?id.268895

CWE Details

CWE IDCWE NameDescription
CWE-841Improper Enforcement of Behavioral WorkflowThe software supports a session in which more than one behavior must be performed by an actor, but it does not properly ensure that the actor performs the behaviors in the required sequence.

CVE Radar

Real-time CVE Intelligence & Vulnerability Management Platform

CVE Radar provides comprehensive vulnerability intelligence by monitoring CVE databases, security advisories, and threat feeds. Get instant updates on new vulnerabilities, exploit details, and mitigation strategies specific to your assets.

Get Free Vulnerability Intelligence AccessAccess real-time CVE monitoring, exploit analysis, and threat intelligence