CVE-2021-43846

MEDIUM

Solidus_frontend <3.1.5-2.11.14 - CSRF

Title source: llm
STIX 2.1

Description

`solidus_frontend` is the cart and storefront for the Solidus e-commerce project. Versions of `solidus_frontend` prior to 3.1.5, 3.0.5, and 2.11.14 contain a cross-site request forgery (CSRF) vulnerability that allows a malicious site to add an item to the user's cart without their knowledge. Versions 3.1.5, 3.0.5, and 2.11.14 contain a patch for this issue. The patch adds CSRF token verification to the "Add to cart" action. Adding forgery protection to a form that missed it can have some side effects. Other CSRF protection strategies as well as a workaround involving modifcation to config/application.rb` are available. More details on these mitigations are available in the GitHub Security Advisory.

References (3)

Core 3

Scores

CVSS v3 5.3
EPSS 0.0013
EPSS Percentile 31.5%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N

Details

CWE
CWE-352
Status published
Products (2)
nebulab/solidus < 2.11.14
rubygems/solidus_frontend 0 - 2.11.14RubyGems
Published Dec 20, 2021
Tracked Since Feb 18, 2026