216.73.217.22

CVE-2011-10019

· Published 13/08/2025 21:15 · Modified 13/08/2025 21:15

Labels: CVE-2011-10019 2025-08-13CVE-2011-10019CWE-94[email protected]

Essential information

Published
13/08/2025 21:15
Modified
13/08/2025 21:15
Author
Creator
CVSS
10.0 CRITICAL (v3) 10.0 CRITICAL (v4.0)
CISA KEV
No
CWE
CVSS vector

CVSS metrics

Description

Spreecommerce versions prior to 0.60.2 contains a remote command execution vulnerability in its search functionality. The application fails to properly sanitize input passed via the search[send][] parameter, which is dynamically invoked using Ruby’s send method. This allows attackers to execute arbitrary shell commands on the server without authentication.

NVD status

Status
Received — CVE has been recently published to the CVE List and has been received by the NVD.
Source
[email protected]
NVD
View on NVD

Affected products (CPE)

ProductCPE
spreecommerce / spreecommerce cpe:2.3:a:spreecommerce:spreecommerce:<0.60.2:*:*:*:*:*:*:*

References