vendor:
TomatoCart
by:
10n1z3d
8,8
CVSS
HIGH
Cross-Site Request Forgery (CSRF)
352
CWE
Product Name: TomatoCart
Affected Version From: 1.0.1
Affected Version To: 1.0.1
Patch Exists: NO
Related CWE: N/A
CPE: a:tomatocart:tomatocart:1.0.1
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: N/A
2010
TomatoCart 1.0.1 Multiple CSRF Vulnerabilities
TomatoCart 1.0.1 is vulnerable to multiple CSRF vulnerabilities. An attacker can exploit these vulnerabilities to create an admin user or change the password of an existing admin user.
Mitigation:
Implementing a CSRF token in the application can help mitigate this vulnerability.