Impact
Drupal AlternativeCommerce (Basket) contains an Improperly Controlled Modification of Dynamically-Determined Object Attributes flaw that permits object injection, allowing an attacker who supplies crafted input to create arbitrary PHP objects and thus execute arbitrary code on the server. The issue is classified as CWE‑915, a classic example of uncontrolled manipulation of object properties based on user input. The consequence is loss of confidentiality, integrity, and availability of the hosting system.
Affected Systems
The vulnerability affects the Drupal AlternativeCommerce (Basket) module for every released version from 0.0.0 to 2.1.17. these module revisions and that have the module enabled and processing user requests, such as shopping carts or checkout flows, are at risk.
Risk and Exploitability
The likely attack vector is the module’s public basket interface, where an attacker can supply crafted input without authentication. Based on the description, it is inferred that no elevated privileges are required to exploit the flaw, so any user with access to the basket can trigger it. The EPSS score of < 1% indicates a very low but non‑zero probability of exploitation, and the vulnerability is not listed in CISA KEV, yet the impact remains severe because attackers could compromise the server if the flaw is leveraged.
OpenCVE Enrichment