The distribution of Zen Cart 1.1.4 before patch 2 includes certain debugging code in the Admin password retrieval functionality, which allows malicious users to gain administrative privileges via password_forgotten.php.
Vulnerable Product | Search on Vulmon | Subscribe to Product |
---|---|---|
zen cart zen cart 1.1.4 |