File Upload Vulnerability in CS Cart by CS-Cart
CVE-2025-50848
6.1MEDIUM
What is CVE-2025-50848?
A file upload vulnerability in CS Cart 4.18.3 permits unrestricted uploading of HTML files. This flaw enables attackers to upload maliciously crafted HTML files, which can be executed directly in users' browsers. With this vulnerability, attackers can deploy fake login forms aimed at credential harvesting or scripts that facilitate Cross-Site Scripting (XSS) attacks. As the content is served from a trusted domain, it amplifies the risk of phishing and script execution against unsuspecting users, making it crucial for organizations to address this vulnerability to safeguard their user data.