PT-2026-99922 · Unknown · Marcoscamara01 Ecommerce Template
CVSS v4.0
6.9
Medium
| Vector | AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
MarcosCamara01 Ecommerce Template versions prior to commit ec97209
Description
Missing authentication in the product cache revalidation Server Action allows a remote, unauthenticated attacker to force the expiration of the entire storefront product cache. The function
revalidateProducts() in src/app/actions.ts calls updateTag("products") without performing session or role checks. Because the file uses the "use server" directive, the function is compiled into a POST-invokable Server Action. The action ID is exposed in a public / next/static chunk, which is not protected by the admin middleware in proxy.ts. When cacheComponents is enabled, the storefront relies on cached entries from getAllProducts(), getCategoryProducts(), and getProduct(). Repeatedly invoking the vulnerable action keeps the cache cold, forcing the application to read the full product catalog from the Postgres database for every request, which degrades storefront availability.Recommendations
Update MarcosCamara01 Ecommerce Template to commit ec97209 or later.
As a temporary workaround, restrict access to the
revalidateProducts() function by implementing a session or role check within src/app/actions.ts.Exploit
Fix
DoS
Missing Authentication
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Marcoscamara01 Ecommerce Template