Vulnerability CVE-2013-5977


Published: 2013-11-01

Description:
Cross-site request forgery (CSRF) vulnerability in Cart66Product.php in the Cart66 Lite plugin before 1.5.1.15 for WordPress allows remote attackers to hijack the authentication of administrators for requests that (1) create or modify products or conduct cross-site scripting (XSS) attacks via the (2) Product name or (3) Price description field in a product save action via a request to wp-admin/admin.php.

See advisories in our WLB2 database:
Topic
Author
Date
Low
WordPress Cart66 1.5.1.14 Cross Site Request Forgery / Cross Site Scripting
absane
12.10.2013

Type:

CWE-352

(Cross-Site Request Forgery (CSRF))

CVSS2 => (AV:N/AC:M/Au:N/C:P/I:P/A:P)

CVSS Base Score
Impact Subscore
Exploitability Subscore
6.8/10
6.4/10
8.6/10
Exploit range
Attack complexity
Authentication
Remote
Medium
No required
Confidentiality impact
Integrity impact
Availability impact
Partial
Partial
Partial
Affected software
Reality66 -> Cart66 lite plugin 
Cart66 -> Cart66 lite plugin 

 References:
http://archives.neohapsis.com/archives/bugtraq/2013-10/0048.html
http://blog.noobroot.com/#!/2013/10/0-day-wordpress-cart66-plugin-15114.html
http://packetstormsecurity.com/files/123587/WordPress-Cart66-1.5.1.14-Cross-Site-Request-Forgery-Cross-Site-Scripting.html
http://seclists.org/bugtraq/2013/Oct/52
http://wordpress.org/plugins/cart66-lite/changelog/
http://www.exploit-db.com/exploits/28959
http://www.securityfocus.com/bid/62975
https://exchange.xforce.ibmcloud.com/vulnerabilities/87874

Copyright 2024, cxsecurity.com

 

Back to Top