RubySec

Providing security resources for the Ruby community

OSVDB-76011 (spree): Spree Search ProductScope Class search[send][] Parameter Arbitrary Command Execution

ADVISORIES

GEM

spree

PATCHED VERSIONS

  • >= 0.60.2

DESCRIPTION

The ProductScope class fails to properly sanitize user-supplied input via the ‘search[send][]’ parameter resulting in arbitrary command execution. With a specially crafted request, a remote attacker can potentially cause arbitrary command execution.

RELATED