GHSA-x485-rhg3-cqr4
CRITICALCVE-2011-10026Spreecommerce versions prior to 0.50.x contain a remote command execution vulnerability in the API's search functionality. Improper input sanitation allows attackers to inject arbitrary shell commands via the search[instanceeval] parameter, which is dynamically invoked using Ruby’s send method. This flaw enables unauthenticated attackers to execute commands on the server.
- Affected
- >= 0.30.0.beta1, < 0.50.0
- Fixed in
- 0.50.0
- Weakness
- CWE-78
- Published
- 2025-08-20
- Source
- github
GHSANVDMITREreferencereferencereferencereferencereferencereferencereferencereferencereference