vendor:
ZeusCart
by:
Tim Coen of Curesec GmbH
7,5
CVSS
HIGH
CSRF
352
CWE
Product Name: ZeusCart
Affected Version From: ZeusCart 4.0
Affected Version To: ZeusCart 4.0
Patch Exists: NO
Related CWE: n/a
CPE: a:zeuscart:zeuscart:4.0
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: None
2015
ZeusCart 4.0: CSRF
None of the forms of Zeuscart have CSRF protection, which means that an attacker can perform actions for the victim if the victim visits an attacker controlled site while logged in.
Mitigation:
This issue was not fixed by the vendor.