Spreecommerce versions prior to 0.50.x contain a remote command execution vulnerability in the API's search functionality. Improper input sanitation allows attackers to inject arbitrary shell commands via the search[instance_eval] parameter, which is dynamically invoked using Ruby’s send method. This flaw enables unauthenticated attackers to execute commands on the server.
The vulnerability results from improper sanitization of the search[instance_eval] parameter passed to the API search function. The value of this parameter is dynamically invoked using Ruby's send method, which allows command injection and execution of arbitrary system shell commands. This mechanism requires no authentication, making the exploit available to any remote attacker.
An unauthenticated attacker can execute arbitrary system commands on the server hosting the application, which in practice means the possibility of complete server takeover, data theft, and further movement within the internal network (lateral movement).
Spreecommerce Spree should be updated to version 0.50.x or newer. Detailed information about security patches is available in the vendor's announcement at the address indicated in the references (spreecommerce.com/blog/2011/04/19/security-fixes).
Spreecommerce Spree in all versions preceding 0.50.x
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:XSpreecommerce Spree
APPSpreecommerce< 0.50.1
Related vulnerabilities
RCE w Spreecommerce Spree — brak sanitizacji parametru wyszukiwania
Spree is an open source e-commerce solution built with Ruby on Rails. A critical IDOR vulnerability exists in ...
Spree is an open source e-commerce solution built with Ruby on Rails. Prior to versions 5.0.8, 5.1.10, 5.2.7, ...
Spree is an open source e-commerce solution built with Ruby on Rails. Prior to versions 4.10.2, 5.0.7, 5.1.9, ...
Spree is a complete open source e-commerce solution built with Ruby on Rails. In Spree from version 3.7 and be...