vendor:
CS-Cart
by:
Ahmed Sultan
8,8
CVSS
HIGH
XXE
611
CWE
Product Name: CS-Cart
Affected Version From: CS-Cart <= 4.3.10
Affected Version To: CS-Cart <= 4.3.10
Patch Exists: YES
Related CWE: N/A
CPE: a:cs-cart:cs-cart
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: Apache on Windows with PHP 5.4.4, Apache on Linux with PHP <5.2.17
2020
CS-Cart <= 4.3.10 XXE Vulnerabilities
Two XXE vulnerabilities were discovered in CS-Cart <= 4.3.10. The first vulnerability is in the Twimgo addon, located in the app/addons/twigmo/Twigmo/Api/ApiData.php file, on line 131. The second vulnerability is in the Amazon payment, located in the app/payments/amazon/amazon_callback.php file, on line 16. An attacker can send a malicious XML request to the vulnerable host, which will cause a GET request to be sent to the attacker's server, indicating a successful attack.
Mitigation:
Upgrade to the latest version of CS-Cart, or apply the patch provided by the vendor.