Executive brief
A security vulnerability exists in the Softtr E-Commerce Pack, a software suite used for managing online retail operations. An attacker can trick an authorized user into performing unintended actions on the platform, such as changing account details or processing unauthorized transactions. This could lead to a loss of administrative control or the exposure of sensitive customer and business data.
Technical details
A Cross-Site Request Forgery (CSRF) vulnerability (CWE-352) exists in the Softtr E-Commerce Pack through version 30072026. The application fails to properly validate unique tokens for state-changing requests, allowing a remote attacker to craft malicious web pages or links. If an authenticated user visits a malicious site while logged into the e-commerce platform, the attacker can execute commands with the victim's privileges. This can result in high impacts to confidentiality and integrity, as well as a partial impact on availability. As of the disclosure date, the vendor has not responded to reports of this vulnerability.
Affected products
- Softtr Information Technology Trade Ltd. Co. E-Commerce Pack through 30072026
Timeline
- 2026-07-30: disclosed: Vulnerability disclosed by TR-CERT (USOM)
- 2026-07-30: advisory: NVD published CVE-2026-5219