Junglewise Threat Intelligence

Thelia authentication bypass for customer and admin accounts

Severity: high · CVSS 7.5 · Published 2024-05-30

Technologies: thelia/thelia (Packagist). Vendors: Packagist.

Executive brief

Thelia, an open-source e-commerce platform, contains a security flaw that allows unauthorized individuals to bypass login requirements. This vulnerability affects both customer and administrator accounts, potentially allowing attackers to modify site content or customer data without valid credentials. This could lead to unauthorized changes to store settings, product listings, or order information.

Technical details

An authentication bypass vulnerability (CWE-287) exists in the Thelia e-commerce project affecting versions from 2.0.0-beta1 up to 2.1.3. The flaw allows a remote attacker to bypass authentication mechanisms for both customer and admin interfaces without requiring any prior privileges or user interaction. Based on the CVSS metrics, the primary impact is on integrity, suggesting that while data may not be directly exfiltrated, it can be modified by an unauthenticated actor. The issue is resolved in versions 2.1.3 and 2.2.0-alpha1.

Affected products

  • Thelia Thelia >= 2.0.0-beta1, < 2.1.3

Timeline

  • 2024-05-30: advisory: GitHub Advisory published
  • 2015-04-13: other: Original security advisory date referenced in metadata
  • 2015-04-13: patched: Fix released in version 2.1.3

References

Related threats