The CartController defines a RateLimiter behavior that is only activated when the 'number' POST/GET parameter is explicitly provided.
When an attacker submits coupon codes against the session-based cart (without passing a 'number' parameter), no rate limiting is applied. This allows unlimited attempts to guess coupon codes.
Vulnerable Code
Complete instructions, including specific configuration details, to reproduce the vulnerability.
An attacker can enumerate all coupon codes through automated requests.
Remediation Apply rate limiting unconditionally on actionUpdateCart regardless of whether 'number' is present.
{
"cwe_ids": [
"CWE-307"
],
"github_reviewed": true,
"github_reviewed_at": "2026-06-19T21:15:26Z",
"nvd_published_at": null,
"severity": "MODERATE"
}