PT-2026-97515 · Unknown · Easy Store
CVE-2026-90903
·
Published
2026-09-23
·
Updated
2026-09-23
CVSS v4.0
7.2
High
| Vector | AV:N/AC:L/AT:N/PR:N/UI:P/VC:L/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X |
Name of the Vulnerable Software and Affected Versions
Easy Store versions 1.0.0 through 3.0.0
Description
The administrator
ApiController fails to validate Cross-Site Request Forgery (CSRF) tokens—a security mechanism that prevents unauthorized commands from being transmitted from a user that the web application trusts—across several administrative AJAX API endpoints. While the products() action is protected, other endpoints including 'orders', 'coupons', 'media', 'customers', 'settings', 'tags', 'categories', 'reviews', and 'collections' accept state-changing requests without verification. This allows an attacker to trick an authenticated administrator into performing unauthorized modifications within the store backend.Recommendations
Update Easy Store to a version where global CSRF verification is implemented in
ApiController::execute() for all state-changing HTTP methods (POST, PUT, PATCH, DELETE) via Session::checkToken().Fix
CSRF
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Easy Store