Executive brief
Thelia, an open-source e-commerce platform, contains a security flaw that allows unauthorized individuals to bypass login requirements. This vulnerability affects both customer and administrator accounts, potentially allowing attackers to modify site content or customer data without valid credentials. This could lead to unauthorized changes to store settings, product listings, or order information.
Technical details
An authentication bypass vulnerability (CWE-287) exists in the Thelia e-commerce project affecting versions from 2.0.0-beta1 up to 2.1.3. The flaw allows a remote attacker to bypass authentication mechanisms for both customer and admin interfaces without requiring any prior privileges or user interaction. Based on the CVSS metrics, the primary impact is on integrity, suggesting that while data may not be directly exfiltrated, it can be modified by an unauthenticated actor. The issue is resolved in versions 2.1.3 and 2.2.0-alpha1.
Affected products
- Thelia Thelia >= 2.0.0-beta1, < 2.1.3
Timeline
- 2024-05-30: advisory: GitHub Advisory published
- 2015-04-13: other: Original security advisory date referenced in metadata
- 2015-04-13: patched: Fix released in version 2.1.3