PT-2009-2227 · Viart · Viart Shop

Published

2009-04-28

·

Updated

2018-10-11

·

CVE-2008-6758

CVSS v2.0

6.8

Medium

VectorAV:N/AC:M/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions: ViArt Shop (aka Shopping Cart) version 3.5
Description: A cross-site request forgery (CSRF) issue allows remote attackers to hijack user authentication for requests that conduct persistent cross-site scripting (XSS) attacks. This is achieved via the cart name parameter in a save action.
Recommendations: For version 3.5, consider restricting access to the cart save.php file until a patch is available. As a temporary workaround, avoid using the cart name parameter in the save action to minimize the risk of exploitation.

Exploit

Fix

CSRF

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2008-6758

Affected Products

Viart Shop