CVE-2010-3978

EPSS 0.64%

Spree allows remote attackers to obtain sensitive information

發布日:2022/5/14修改日:2024/12/5

描述

Spree 0.11.x before 0.11.2 and 0.30.x before 0.30.0 exchanges data using JavaScript Object Notation (JSON) without a mechanism for validating requests, which allows remote attackers to obtain sensitive information via vectors involving (1) `admin/products.json`, (2) `admin/users.json`, or (3) `admin/overview/get_report_data`, related to a "JSON hijacking" issue.

受影響套件(1)

參考連結(12)