CVE-2008-7310

Spree 0.2.0 - Unauthenticated Order State Manipulation via Mass Assignment

Title source: llm
STIX 2.1

Description

Spree 0.2.0 does not properly restrict the use of a hash to provide values for a model's attributes, which allows remote attackers to set the Order state value and bypass the intended payment step via a modified URL, related to a "mass assignment" vulnerability.

Scores

EPSS 0.0016
EPSS Percentile 36.2%

Details

CWE
CWE-255
Status published
Products (2)
rubygems/spree 0 - 0.4.0RubyGems
spreecommerce/spree 0.2.0
Published Apr 05, 2012
Tracked Since Feb 18, 2026