Vulnerability Description
The ShipStation.com plugin 1.0 for CS-Cart allows remote attackers to obtain sensitive information (via action=export) because a typo results in a successful comparison of a blank password and NULL.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Shipstation | Shipstation | 1.0 |
References
- https://www.jerdiggity.com/node/869ExploitThird Party Advisory
- https://www.jerdiggity.com/node/871ExploitThird Party Advisory
- https://www.jerdiggity.com/node/869ExploitThird Party Advisory
- https://www.jerdiggity.com/node/871ExploitThird Party Advisory
FAQ
What is CVE-2020-8889?
CVE-2020-8889 is a vulnerability with a CVSS score of 7.5 (HIGH). The ShipStation.com plugin 1.0 for CS-Cart allows remote attackers to obtain sensitive information (via action=export) because a typo results in a successful comparison of a blank password and NULL.
How severe is CVE-2020-8889?
CVE-2020-8889 has been rated HIGH with a CVSS base score of 7.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2020-8889?
Check the references section above for vendor advisories and patch information. Affected products include: Shipstation Shipstation.