PT-2017-15203 · Cs Cart · Cs-Cart Japanese Edition+1

Hirota Kazuki

·

Published

2017-08-02

·

Updated

2023-01-10

·

CVE-2017-2138

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions CS-Cart Japanese Edition versions 4.3.10 and earlier (excluding v2 and v3) CS-Cart Multivendor Japanese Edition versions 4.3.10 and earlier (excluding v2 and v3)
Description A cross-site request forgery (CSRF) issue allows remote attackers to hijack the authentication of administrators via unspecified vectors.
Recommendations For CS-Cart Japanese Edition versions 4.3.10 and earlier (excluding v2 and v3), update to a version later than 4.3.10. For CS-Cart Multivendor Japanese Edition versions 4.3.10 and earlier (excluding v2 and v3), update to a version later than 4.3.10.

Fix

CSRF

Weakness Enumeration

Related Identifiers

CVE-2017-2138

Affected Products

Cs-Cart Japanese Edition
Cs-Cart Multivendor Japanese Edition