Junglewise Threat Intelligence

CVE-2025-13004: Farktor Software E-Commerce Package auth bypass in user-controlled variables

CVE-2025-13004 · Severity: medium · CVSS 6.3 · Published 2026-02-12

Technologies: Farktor Software E-Commerce Services Inc. E-Commerce Package. Vendors: Farktor.

Executive brief

Farktor Software's E-Commerce Package, a platform used for managing online retail operations, contains a security flaw that allows users to bypass authorization checks. By manipulating specific data keys or variables, an attacker could potentially modify information they are not authorized to access. This could lead to unauthorized changes in order details, customer profiles, or other sensitive business data, impacting the integrity of the e-commerce operations.

Technical details

An Authorization Bypass Through User-Controlled Key (CWE-639) vulnerability exists in the Farktor Software E-Commerce Package through version 27112025. The flaw resides in how the application handles user-provided keys or variables, failing to properly validate that the requesting user has the authority to access or modify the object associated with that key. An attacker with low-privileged credentials can exploit this over the network, though it may require some user interaction. Successful exploitation allows the attacker to manipulate variables and bypass security logic to perform unauthorized data modifications.

Affected products

  • Farktor Software E-Commerce Services Inc. E-Commerce Package through 27112025

Timeline

  • 2026-02-12: advisory: Initial disclosure by TR-CERT (USOM)
  • 2026-02-12: disclosed

References

Related threats