osCommerce Phoenix CE before 1.0.5.4 allows admin/define_language.php CSRF.
The web application does not, or cannot, sufficiently verify whether a request was intentionally provided by the user who sent the request, which could have originated from an unauthorized actor.
Link | Tags |
---|---|
https://herolab.usd.de/security-advisories/usd-2020-0027/ | third party advisory exploit |