Vulnerability Description
ZeusCart 4.0 contains a cross-site request forgery vulnerability that allows attackers to perform unauthorized actions on behalf of victims by crafting malicious requests. Attackers can deactivate customer accounts via the admin interface by tricking users into visiting attacker-controlled pages that submit requests to the regstatus endpoint with action=deny parameters.
CVSS Score
MEDIUM
Related Weaknesses (CWE)
References
- http://http://www.zeuscart.com/
- https://www.exploit-db.com/exploits/46027
- https://www.vulncheck.com/advisories/zeuscart-deactivate-customer-accounts-csrf
FAQ
What is CVE-2018-25435?
CVE-2018-25435 is a vulnerability with a CVSS score of 5.3 (MEDIUM). ZeusCart 4.0 contains a cross-site request forgery vulnerability that allows attackers to perform unauthorized actions on behalf of victims by crafting malicious requests. Attackers can deactivate cus...
How severe is CVE-2018-25435?
CVE-2018-25435 has been rated MEDIUM with a CVSS base score of 5.3/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2018-25435?
Check the references section above for vendor advisories and patch information. Review vendor security bulletins for remediation guidance.