CVE-2011-10019

Spreecommerce versions prior to 0.60.2 contains a remote command execution vulnerability in its search functionality. The application fails to properly sanitize input passed via the search[send][] parameter, which is dynamically invoked using Ruby’s send method. This allows attackers to execute arbitrary shell commands on the server without authentication.
CVSS

No CVSS.

Configurations

No configuration.

History

18 Aug 2025, 21:15

Type Values Removed Values Added
References
  • () https://github.com/orgs/spree -

13 Aug 2025, 21:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-08-13 21:15

Updated : 2025-08-18 21:15


NVD link : CVE-2011-10019

Mitre link : CVE-2011-10019


JSON object : View

Products Affected

No product.

CWE

No CWE.