PT-2009-2227 · Viart · Viart Shop
Published
2009-04-28
·
Updated
2018-10-11
·
CVE-2008-6758
CVSS v2.0
6.8
Medium
| Vector | AV:N/AC:M/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions:
ViArt Shop (aka Shopping Cart) version 3.5
Description:
A cross-site request forgery (CSRF) issue allows remote attackers to hijack user authentication for requests that conduct persistent cross-site scripting (XSS) attacks. This is achieved via the
cart name parameter in a save action.Recommendations:
For version 3.5, consider restricting access to the cart save.php file until a patch is available. As a temporary workaround, avoid using the
cart name parameter in the save action to minimize the risk of exploitation.Exploit
Fix
CSRF
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Viart Shop