Cross-site request forgery (CSRF) vulnerability in CubeCart prior to 6.5.3 allows a remote unauthenticated attacker to delete data in the system.
The web application does not, or cannot, sufficiently verify whether a request was intentionally provided by the user who sent the request, which could have originated from an unauthorized actor.
Link | Tags |
---|---|
https://forums.cubecart.com/topic/58736-cubecart-653-released-security-update/ | vendor advisory |
https://jvn.jp/en/jp/JVN22220399/ | third party advisory patch |