Configuration in CS‑Cart CS-Cart



Published: 2013-02-24 | Updated: 2020-08-11
Risk Medium
Patch available YES
Number of vulnerabilities 1
CVE-ID CVE-2013-0118
CWE-ID CWE-16
Exploitation vector Network
Public exploit N/A
Vulnerable software
Subscribe
CS-Cart
Web applications / CMS

Vendor CS‑Cart

Security Bulletin

This security bulletin contains one medium risk vulnerability.

1) Configuration

EUVDB-ID: #VU43062

Risk: Medium

CVSSv3.1: 4.6 [CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N/E:U/RL:O/RC:C]

CVE-ID: CVE-2013-0118

CWE-ID: CWE-16 - Configuration

Exploit availability: No

Description

The vulnerability allows a remote non-authenticated attacker to manipulate data.

CS-Cart before 3.0.6, when PayPal Standard Payments is configured, allows remote attackers to set the payment recipient via a modified value of the merchant's e-mail address, as demonstrated by setting the recipient to one's self.

Mitigation

Install update from vendor's website.

Vulnerable software versions

CS-Cart: 3.0 - 3.0.4

External links

http://www.kb.cert.org/vuls/id/583564
http://www.kb.cert.org/vuls/id/BLUU-949PQL


Q & A

Can this vulnerability be exploited remotely?

Yes. This vulnerability can be exploited by a remote non-authenticated attacker via the Internet.

Is there known malware, which exploits this vulnerability?

No. We are not aware of malware exploiting this vulnerability.



###SIDEBAR###