5
CVSSv2

CVE-2013-0118

Published: 24/02/2013 Updated: 25/02/2013
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
VMScore: 445
Vector: AV:N/AC:L/Au:N/C:N/I:P/A:N

Vulnerability Summary

CS-Cart prior to 3.0.6, when PayPal Standard Payments is configured, allows remote malicious users to set the payment recipient via a modified value of the merchant's e-mail address, as demonstrated by setting the recipient to one's self.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

cs-cart cs-cart 3.0.2

cs-cart cs-cart 3.0

cs-cart cs-cart 3.0.3

cs-cart cs-cart 3.0.4

cs-cart cs-cart