3.7
CVSSv3

CVE-2020-9009

Published: 11/04/2023 Updated: 21/04/2023
CVSS v3 Base Score: 3.7 | Impact Score: 1.4 | Exploitability Score: 2.2
VMScore: 0

Vulnerability Summary

The ShipStation.com plugin 1.1 and previous versions for CS-Cart allows remote malicious users to insert arbitrary information into the database (via action=shipnotify) because access to this endpoint is completely unchecked. The attacker must guess an order number.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

shipstation shipstation