Skip to main content
Mallory
Medium

CSRF in Oracle iStore Shopping Cart

IdentifiersCVE-2025-30746CWE-352· Cross-Site Request Forgery (CSRF)

CVE-2025-30746 is an easily exploitable vulnerability in the Shopping Cart component of Oracle iStore within Oracle E-Business Suite, affecting supported versions 12.2.3 through 12.2.14. The available supporting content indicates the issue is reachable over HTTP by an unauthenticated attacker and requires user interaction by a separate victim user. CISA ADP enrichment maps the weakness to CWE-352, indicating a cross-site request forgery condition. Successful exploitation can cause the victim’s browser to submit unintended requests to Oracle iStore, resulting in unauthorized update, insert, or delete operations on some Oracle iStore-accessible data, as well as unauthorized read access to a subset of accessible data. The CVSS v3.1 vector (AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N) also indicates scope change, meaning exploitation in Oracle iStore may significantly affect additional products or components beyond the vulnerable application boundary.

Share:
For your environment

Are you exposed to this one?

Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.

ANALYST BRIEF

Impact, mitigation & remediation

What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.

Impact

What an attacker gets, and what they’ve been doing with it.

Successful exploitation allows an unauthenticated remote attacker to induce unauthorized actions in Oracle iStore in the context of a victim user session. The documented impact includes unauthorized modification of some iStore-accessible data, specifically update, insert, and delete operations, and unauthorized read access to a subset of iStore-accessible data. Integrity and confidentiality impacts are both low per CVSS, while availability impact is none. Because the scope is changed, the effects may extend beyond Oracle iStore itself and significantly impact additional connected products or components in the Oracle E-Business Suite environment.

Mitigation

If you can’t patch tonight, do this now.

Until patching is completed, reduce exposure of Oracle iStore over HTTP/HTTPS to untrusted networks where possible, require strong session protections, and monitor for suspicious state-changing requests involving the Shopping Cart workflow. Because exploitation requires user interaction, practical mitigations include limiting user exposure to untrusted web content, enforcing browser and email security controls to reduce phishing or malicious link delivery, and reviewing application-side anti-CSRF protections for sensitive transactions. Additional defensive steps include auditing Oracle E-Business Suite logs for unexpected update/insert/delete activity and reviewing access patterns for anomalous reads of iStore-accessible data.

Remediation

Patch, then assume compromise.

Apply Oracle’s fix for CVE-2025-30746 as provided in the July 2025 Oracle Critical Patch Update. The affected supported versions are Oracle iStore 12.2.3 through 12.2.14, and Oracle’s advisory indicates patches are available through the Oracle E-Business Suite patching process and Patch Availability Documents. Organizations should prioritize patching internet-reachable Oracle E-Business Suite deployments, especially Oracle iStore Shopping Cart instances, and validate that the July 2025 CPU has been fully applied across all relevant application tiers.
PUBLIC EXPLOITS

Exploits

No public exploits tracked yet. Mallory keeps watching.

VALID 0 / 0 TOTALView more in app

No public exploit code observed for this vulnerability.

EXPOSURE SURFACE

Affected products & vendors

Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.

VendorProductType
OracleIstoreapplication

Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.

What this page doesn’t show

The version that knows your environment.

This page is what’s public. Mallory adds the parts that aren’t: which of your assets are affected, which adversaries are exploiting it right now, which detections to deploy, and what to do tonight.
Exposure mapping

Query your assets running an affected version, and investigate the blast radius.

Threat actor evidence1

Every observed campaign linking this CVE to a named adversary.

Associated malware2

Malware families riding this exploit, with evidence and IOCs.

Detection signatures

YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.

Vendor-by-vendor mapping

Cross-references every affected SKU, including bundled OEM variants.

Social activity1

Community discussion across Reddit, Mastodon, and other social sources.