Description
The ShipStation.com plugin 1.1 and earlier for CS-Cart allows remote attackers to insert arbitrary information into the database (via action=shipnotify) because access to this endpoint is completely unchecked. The attacker must guess an order number.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2020-29840 | The ShipStation.com plugin 1.1 and earlier for CS-Cart allows remote attackers to insert arbitrary information into the database (via action=shipnotify) because access to this endpoint is completely unchecked. The attacker must guess an order number. |
References
History
Tue, 11 Feb 2025 18:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2025-02-11T17:35:54.860Z
Reserved: 2020-02-16T00:00:00.000Z
Link: CVE-2020-9009
Updated: 2024-08-04T10:19:19.823Z
Status : Modified
Published: 2023-04-11T21:15:10.363
Modified: 2025-02-11T18:15:19.830
Link: CVE-2020-9009
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD