Impact
Craft Commerce's CartController applies its rate limiter only when the 'number' parameter is present in POST or GET requests. An unauthenticated attacker who omits this parameter can repeatedly submit couponCode values to the actionUpdateCart endpoint for the session-based cart, preventing the creation of the IP rate-limit identity and allowing unlimited automated coupon-code guessing and enumeration. This vulnerability, indicative of CWE‑307, is fixed in versions 4.11.2 and 5.6.5.
Affected Systems
The flaw affects Craft Commerce versions 4.0.0 through 4.11.2 and 5.6.5. The issue was fixed in releases 4.11.2 and 5.6.5. All installations using the older versions of these branches are vulnerable.
Risk and Exploitability
The CVSS score of 6.9 reflects a moderate severity and the fact that the EPSS score of < 1% indicates a very low exploitation probability, and the vulnerability is not yet listed in CISA KEV. The attack vector is remote via the web interface; authentication is not required, and the exploitation is straightforward: send successive couponCode POST requests to the cart update action. Once the limiter is bypassed, an attacker can enumerate valid coupon codes at near-zero cost.
OpenCVE Enrichment
Github GHSA