PT-2026-97515 · Unknown · Easy Store

CVE-2026-90903

·

Published

2026-09-23

·

Updated

2026-09-23

CVSS v4.0

7.2

High

VectorAV:N/AC:L/AT:N/PR:N/UI:P/VC:L/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Name of the Vulnerable Software and Affected Versions Easy Store versions 1.0.0 through 3.0.0
Description The administrator ApiController fails to validate Cross-Site Request Forgery (CSRF) tokens—a security mechanism that prevents unauthorized commands from being transmitted from a user that the web application trusts—across several administrative AJAX API endpoints. While the products() action is protected, other endpoints including 'orders', 'coupons', 'media', 'customers', 'settings', 'tags', 'categories', 'reviews', and 'collections' accept state-changing requests without verification. This allows an attacker to trick an authenticated administrator into performing unauthorized modifications within the store backend.
Recommendations Update Easy Store to a version where global CSRF verification is implemented in ApiController::execute() for all state-changing HTTP methods (POST, PUT, PATCH, DELETE) via Session::checkToken().

Fix

CSRF

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-90903

Affected Products

Easy Store