CVE-2015-2701
Cross-site request forgery (CSRF) vulnerability in CS-Cart 4.2.4 allows remote attackers to hijack the authentication of users for requests that change a user password via a request to profiles-update/.
- Affected products
- Cs-Cart
- Cs-cart
- = 4.2.4
- Fix
- Available
- CVSS 2.0
- 6.8 MEDIUM
- EPSS
- 2.7% (85th percentile)
- Weakness
- CWE-352
- NVD status
- Modified
- Published
- 2015-03-25
CVE-2015-2701 at NVD
1 known exploit for CVE-2015-2701
Proof-of-concept code and exploit modules indexed by Sploitus