Vulnerabilities
Vulnerable Software
Sparksolutions:  >> Spree  Security Vulnerabilities
In Spree before versions 3.7.11, 4.0.4, or 4.1.11, expired user tokens could be used to access Storefront API v2 endpoints. The issue is patched in versions 3.7.11, 4.0.4 and 4.1.11. A workaround without upgrading is described in the linked advisory.
CVSS Score
7.4
EPSS Score
0.011
Published
2020-10-20


Contact Us

Shodan ® - All rights reserved