Vulnerability Description
An issue was discovered in CS Cart 4.18.3 allows the vendor login functionality lacks essential security controls such as CAPTCHA verification and rate limiting. This allows an attacker to systematically attempt various combinations of usernames and passwords (brute-force attack) to gain unauthorized access to vendor accounts. The absence of any blocking mechanism makes the login endpoint susceptible to automated attacks.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Cs-Cart | Cs-Cart | 4.18.3 |
Related Weaknesses (CWE)
References
- http://cs.comNot Applicable
- https://github.com/hackerwahab/CS-Cart-Vulns/blob/main/CVE-2025-50850.mdThird Party Advisory
FAQ
What is CVE-2025-50850?
CVE-2025-50850 is a vulnerability with a CVSS score of 8.6 (HIGH). An issue was discovered in CS Cart 4.18.3 allows the vendor login functionality lacks essential security controls such as CAPTCHA verification and rate limiting. This allows an attacker to systematica...
How severe is CVE-2025-50850?
CVE-2025-50850 has been rated HIGH with a CVSS base score of 8.6/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2025-50850?
Check the references section above for vendor advisories and patch information. Affected products include: Cs-Cart Cs-Cart.