Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2011-5240 | Spreecommerce versions prior to 0.60.2 contains a remote command execution vulnerability in its search functionality. The application fails to properly sanitize input passed via the search[send][] parameter, which is dynamically invoked using Ruby’s send method. This allows attackers to execute arbitrary shell commands on the server without authentication. |
Github GHSA |
GHSA-97vm-c39p-jr86 | Spree has Remote Command Execution vulnerability in search functionality |
Wed, 24 Sep 2025 00:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Spreecommerce
Spreecommerce spree |
|
| CPEs | cpe:2.3:a:spreecommerce:spree:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Spreecommerce
Spreecommerce spree |
|
| Metrics |
cvssV3_1
|
Mon, 18 Aug 2025 21:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
Thu, 14 Aug 2025 15:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Wed, 13 Aug 2025 21:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Spreecommerce versions prior to 0.60.2 contains a remote command execution vulnerability in its search functionality. The application fails to properly sanitize input passed via the search[send][] parameter, which is dynamically invoked using Ruby’s send method. This allows attackers to execute arbitrary shell commands on the server without authentication. | |
| Title | Spreecommerce < 0.60.2 Search Parameter RCE | |
| Weaknesses | CWE-1321 CWE-94 |
|
| References |
|
|
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-05-15T11:13:42.139Z
Reserved: 2025-08-13T18:01:12.138Z
Link: CVE-2011-10019
Updated: 2025-08-14T13:45:34.705Z
Status : Analyzed
Published: 2025-08-13T21:15:29.543
Modified: 2025-09-24T00:31:10.940
Link: CVE-2011-10019
No data.
OpenCVE Enrichment
No data.
EUVD
Github GHSA