Impact
The vulnerability is a missing authentication check in the revalidateProducts server action. Because the action is exported from a file-scoped "use server" module, it is compiled into a public POST-invokable endpoint. An unauthenticated requester can identify the action’s ID in the public JavaScript bundle and call it to trigger updateTag("products"), causing the entire storefront cache to expire. This results in the storefront operating at full database load for an extended period, effectively denying service to legitimate users. The weakness is identified as CWE-306.
Affected Systems
The affected product is MarcosCamara01 Ecommerce Template. All releases prior to the commit ec97209 are vulnerable. The issue is tied to the server action defined in src/app/actions.ts and exposed to client components that import it.
Risk and Exploitability
The vulnerability has a CVSS score of 6.9, indicating medium severity. The EPSS score is not available, and it is not listed in CISA KEV, but the risk remains significant because the attack requires no authentication and a single POST request to the server action. Given the low complexity and the obvious impact of cache exhaustion, a remote attacker can cause widespread service degradation with minimal effort. The likely attack vector is a remote unauthenticated POST request to the server action, triggered by extracting the action ID from the public bundle.
OpenCVE Enrichment