vendor:
Bonza Cart
by:
G4N0K
9.8
CVSS
CRITICAL
Admin Password Changing Exploit
287
CWE
Product Name: Bonza Cart
Affected Version From: <= 1.10
Affected Version To:
Patch Exists: NO
Related CWE:
CPE:
Platforms Tested:
2008
Bonza Cart <= 1.10 Admin Password Changing Exploit
This exploit allows an attacker to change the admin password in Bonza Cart version 1.10 or lower. The vulnerability is due to a lack of proper input validation, allowing an attacker to modify the password field and gain unauthorized access to the admin account.
Mitigation:
Upgrade to a patched version of Bonza Cart or apply the vendor-provided patch. Ensure that input validation is implemented correctly to prevent unauthorized modification of sensitive data.