vendor:
ASPMass Shopping Cart
by:
Abysssec Inc
7.5
CVSS
HIGH
CSRF
352
CWE
Product Name: ASPMass Shopping Cart
Affected Version From: ASPMass Shopping Cart 0.1
Affected Version To:
Patch Exists: NO
Related CWE:
CPE:
Platforms Tested:
Unknown
ASPMass Shopping Cart Vulnerability File Upload CSRF
This version of ASP Shopping Cart has CSRF vulnerability for upload a file with fckEditor. The vulnerability requires the admin's cookie and bypassing a specific file extension implemented by FckEditor v2.
Mitigation:
Implement proper input validation and CSRF protection mechanisms.