Cross-Site Request Forgery in ZeusCart Affects User Account Management
CVE-2018-25435
Key Information:
Badges
What is CVE-2018-25435?
ZeusCart 4.0 is susceptible to a cross-site request forgery vulnerability that enables attackers to execute unauthorized actions by tricking victims into loading malicious links. This exploit allows attackers to deactivate customer accounts through a crafted request sent to the regstatus endpoint with an action=deny parameter, potentially disrupting user access and affecting account integrity. It highlights the importance of implementing anti-CSRF tokens to bolster security and protect users from such exploitations.
Affected Version(s)
ZeusCart 4.0
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
CVSS V4
Timeline
- ๐ก
Public PoC available
- ๐พ
Exploit known to exist
Vulnerability published
Vulnerability Reserved
