Description
Cross-Site request forgery (CSRF) vulnerability in Softtr Information Technology Trade Ltd. Co. E-Commerce Pack allows Cross Site Request Forgery.

This issue affects E-Commerce Pack: before 5.03.01.49.
Published: 2026-07-30
Score: 8.3 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability is a classic CSRF flaw (CWE‑352) that allows an attacker to force an authenticated user of Softtr’s E‑Commerce Pack to perform state‑changing operations without consent. This flaw can lead to unauthorized modification of orders, account information, or other sensitive operations, violating data integrity and potentially exposing confidential data.

Affected Systems

Softtr Information Technology Trade Ltd. Co. distributes the E‑Commerce Pack, and all builds prior to version 5.03.01.49 are affected. Systems running any earlier version must verify whether an update that removes the flaw has been released by the vendor.

Risk and Exploitability

The CVSS score of 8.3 classifies the issue as high severity. An EPSS score of <1% indicates a very low probability of exploitation in the wild. The flaw is not listed in CISA’s KEV catalog. Likely attack vector: an attacker would need a victim who is already authenticated to the E‑Commerce Pack and who visits a malicious or compromised web page that submits a forged request on behalf of the victim. No official patch or workaround has been published yet, so the risk remains until the vendor releases a fix or the customer implements mitigating controls.

Generated by OpenCVE AI on August 4, 2026 at 11:44 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Confirm whether a patched version of Softtr’s E‑Commerce Pack is available from the vendor, and upgrade to that version if so.
  • Implement strict CSRF protection, such as proper token validation and same‑site cookie attributes, for all state‑changing requests.
  • Configure a web‑application firewall or server rule to detect and block suspicious POST or PUT requests lacking valid CSRF tokens or with forged headers.

Generated by OpenCVE AI on August 4, 2026 at 11:44 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 31 Jul 2026 14:00:00 +0000

Type Values Removed Values Added
Description Cross-Site request forgery (CSRF) vulnerability in Softtr Information Technology Trade Ltd. Co. E-Commerce Pack allows Cross Site Request Forgery. This issue affects E-Commerce Pack: through 30072026. NOTE: The vendor was contacted early about this disclosure but did not respond in any way. Cross-Site request forgery (CSRF) vulnerability in Softtr Information Technology Trade Ltd. Co. E-Commerce Pack allows Cross Site Request Forgery. This issue affects E-Commerce Pack: before 5.03.01.49.

Thu, 30 Jul 2026 20:45:00 +0000

Type Values Removed Values Added
First Time appeared Softtr
Softtr e-commerce Pack
Vendors & Products Softtr
Softtr e-commerce Pack

Thu, 30 Jul 2026 16:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Thu, 30 Jul 2026 14:15:00 +0000

Type Values Removed Values Added
Description Cross-Site request forgery (CSRF) vulnerability in Softtr Information Technology Trade Ltd. Co. E-Commerce Pack allows Cross Site Request Forgery. This issue affects E-Commerce Pack: through 30072026. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.
Title CSRF in Softtr's E-Commerce Pack
Weaknesses CWE-352
References
Metrics cvssV3_1

{'score': 8.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:L'}


Subscriptions

Softtr E-commerce Pack
cve-icon MITRE

Status: PUBLISHED

Assigner: TR-CERT

Published:

Updated: 2026-07-31T13:27:29.128Z

Reserved: 2026-03-31T11:50:13.083Z

Link: CVE-2026-5219

cve-icon Vulnrichment

Updated: 2026-07-30T15:14:43.777Z

cve-icon NVD

Status : Deferred

Published: 2026-07-30T14:17:01.747

Modified: 2026-07-31T14:16:50.457

Link: CVE-2026-5219

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-04T11:45:03Z

Weaknesses
  • CWE-352

    Cross-Site Request Forgery (CSRF)