The requests which add an image to the cart and remove it again were plain links without a token. A prepared page on another web site could therefore change the cart of a visitor. The buyer sees the cart again before an order is placed.
- Needed: no account. The victim is any visitor of the shop who opens a prepared page.
- Affected: all versions before 6.5.0, 4.3.3 included.
- Fixed in: 6.5.0. The cart requests need the form token. Not fixed in 4.3.3, because the fix needs new scripts in the cart.
-
Severity: CVSS 4.0 6.9 (
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N), CWE-352. - CVE: CVE-2026-100748.
All prices include VAT. The gross price will vary depending on the selected shipping country.