CVE-2010-3978

Spree 0.11.0-0.11.1 and 0.30.x < 0.30.0 - Unauthenticated Sensitive Information Exposure via JSON Hijacking

Title source: llm
STIX 2.1

Description

Spree 0.11.x before 0.11.2 and 0.30.x before 0.30.0 exchanges data using JavaScript Object Notation (JSON) without a mechanism for validating requests, which allows remote attackers to obtain sensitive information via vectors involving (1) admin/products.json, (2) admin/users.json, or (3) admin/overview/get_report_data, related to a "JSON hijacking" issue.

Scores

EPSS 0.0063
EPSS Percentile 70.6%

Details

CWE
CWE-200
Status published
Products (4)
rubygems/spree 0.11.0 - 0.11.2RubyGems
spreecommerce/spree 0.11.0
spreecommerce/spree 0.11.1
spreecommerce/spree 0.30.0 beta1
Published Nov 17, 2010
Tracked Since Feb 18, 2026