Vulnerability Description
The ShipStation.com plugin 1.1 and earlier for CS-Cart allows remote attackers to insert arbitrary information into the database (via action=shipnotify) because access to this endpoint is completely unchecked. The attacker must guess an order number.
CVSS Score
LOW
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Shipstation | Shipstation | <= 1.1 |
Related Weaknesses (CWE)
References
- https://help.shipstation.com/hc/en-us/articles/360025855352-CS-CartNot Applicable
- https://www.jerdiggity.com/node/870ExploitPatchThird Party Advisory
- https://help.shipstation.com/hc/en-us/articles/360025855352-CS-CartNot Applicable
- https://www.jerdiggity.com/node/870ExploitPatchThird Party Advisory
FAQ
What is CVE-2020-9009?
CVE-2020-9009 is a vulnerability with a CVSS score of 3.7 (LOW). The ShipStation.com plugin 1.1 and earlier for CS-Cart allows remote attackers to insert arbitrary information into the database (via action=shipnotify) because access to this endpoint is completely u...
How severe is CVE-2020-9009?
CVE-2020-9009 has been rated LOW with a CVSS base score of 3.7/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2020-9009?
Check the references section above for vendor advisories and patch information. Affected products include: Shipstation Shipstation.