Impact
The vulnerability is a classic CSRF flaw (CWE‑352) that allows an attacker to force an authenticated user of Softtr’s E‑Commerce Pack to perform state‑changing operations without consent. This flaw can lead to unauthorized modification of orders, account information, or other sensitive operations, violating data integrity and potentially exposing confidential data.
Affected Systems
Softtr Information Technology Trade Ltd. Co. distributes the E‑Commerce Pack, and all builds prior to version 5.03.01.49 are affected. Systems running any earlier version must verify whether an update that removes the flaw has been released by the vendor.
Risk and Exploitability
The CVSS score of 8.3 classifies the issue as high severity. An EPSS score of <1% indicates a very low probability of exploitation in the wild. The flaw is not listed in CISA’s KEV catalog. Likely attack vector: an attacker would need a victim who is already authenticated to the E‑Commerce Pack and who visits a malicious or compromised web page that submits a forged request on behalf of the victim. No official patch or workaround has been published yet, so the risk remains until the vendor releases a fix or the customer implements mitigating controls.
OpenCVE Enrichment