Impact
The quick question admin feature allows injection of arbitrary Perl code. Normally the code runs inside a Safe container that limits operations, but when the AllowGlobal directive is enabled for a catalog the container is bypassed, giving the injected code full server privileges. This flaw means an attacker can execute any Perl code on the host that runs the Interchange application.
Affected Systems
Deployments of the Interchange e‑commerce platform that expose the quick question admin functionality are vulnerable. The vulnerability is not tied to a specific version in the description, so any installation that includes the unpatched feature is at risk. Administrators should check whether the AllowGlobal setting is enabled for their catalogs and whether the admin function is active.
Risk and Exploitability
The vulnerability is not reported in a KEV catalog and no EPSS score is available, but it permits unauthenticated remote exploitation through the web interface. Attackers can send a crafted request to the admin endpoint and immediately gain code execution on the server. Inferred that the attack vector functions via an unauthenticated HTTP request targeting the admin endpoint. Because the attacker receives full control, the risk remains high despite the absence of an EPSS value.
OpenCVE Enrichment