vendor:
CS-Cart
by:
Luis Santana
6.8
CVSS
MEDIUM
Cross-Site Request Forgery (CSRF)
352
CWE
Product Name: CS-Cart
Affected Version From: 4.2.2004
Affected Version To: 4.2.2004
Patch Exists: NO
Related CWE: N/A
CPE: a:cs-cart:cs-cart:4.2.4
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: Linux + PHP
2015
CS-Cart 4.2.4 CSRF
Standard CSRF, allow you to change a users's password.
Mitigation:
Implementing CSRF protection tokens, validating input, and using secure communication protocols.