vendor:
Hucart cms
by:
AllenChen
8.8
CVSS
HIGH
CSRF
352
CWE
Product Name: Hucart cms
Affected Version From: v5.7.4
Affected Version To: v5.7.4
Patch Exists: YES
Related CWE: CVE-2019-6249
CPE: a:hucart:hucart_cms
Metasploit:
N/A
Other Scripts:
N/A
Platforms Tested: None
2019
Hucart cms v5.7.4 CSRF vulnerability add administrator account
An issue was discovered in HuCart v5.7.4. There is a CSRF vulnerability that can add an admin account via /adminsys/index.php?load=admins&act=edit_info&act_type=add.
Mitigation:
Implementing a secure configuration posture, including the application of security patches, can reduce the risk of exploitation of this vulnerability.