vendor:
Online Shopping Ecommerce Cart
by:
L0RD
7.5
CVSS
HIGH
Persistent Cross-Site scripting / Cross site request forgery / Authentication bypass
CWE
Product Name: Online Shopping Ecommerce Cart
Affected Version From: 1
Affected Version To: 1
Patch Exists: NO
Related CWE:
CPE:
Platforms Tested: Kali linux
2018
SuperCom Online Shopping Ecommerce Cart 1 – Persistent Cross-Site scripting / Cross site request forgery / Authentication bypass
SuperCom - Online Shopping Ecommerce Cart 1 suffers from multiple vulnerabilities. The first vulnerability is persistent cross-site scripting where an attacker can inject malicious code into the profile update section, which will then execute when the user views their profile. The second vulnerability is cross-site request forgery where an attacker can change the user's authentication directly by creating a malicious form that submits to the update profile endpoint. The third vulnerability is authentication bypass where an attacker can bypass the authentication by using a specific username and password combination.
Mitigation:
The vendor should release a patch that fixes these vulnerabilities. Users should update to the latest version of the software. Additionally, users should be cautious when inputting sensitive information and should only use trusted websites.