File Upload Vulnerability in CS Cart by CS-Cart
CVE-2025-50848

6.1MEDIUM

Key Information:

Vendor

CS-Cart

Status
Vendor
CVE Published:
31 July 2025

What is CVE-2025-50848?

A file upload vulnerability in CS Cart 4.18.3 permits unrestricted uploading of HTML files. This flaw enables attackers to upload maliciously crafted HTML files, which can be executed directly in users' browsers. With this vulnerability, attackers can deploy fake login forms aimed at credential harvesting or scripts that facilitate Cross-Site Scripting (XSS) attacks. As the content is served from a trusted domain, it amplifies the risk of phishing and script execution against unsuspecting users, making it crucial for organizations to address this vulnerability to safeguard their user data.

References

CVSS V3.1

Score:
6.1
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.