Home
Trends
Vulnerabilities
News
Researchers
Why dbugs?

Allenchen

#29691of 53,619
8.8Total CVSS
Vulnerabilities · 1
PT-2019-18054
8.8
2019-01-13
Hucart · Hucart · CVE-2019-6249
**Name of the Vulnerable Software and Affected Versions** HuCart version 5.7.4 **Description** A CSRF issue allows adding an admin account via the /adminsys/index.php?load=admins&act=edit info&act type=add API endpoint. **Recommendations** For HuCart version 5.7.4, as a temporary workaround, consider restricting access to the /adminsys/index.php?load=admins&act=edit info&act type=add API endpoint until a patch is available. At the moment, there is no information about a newer version that contains a fix for this issue.