The ShipStation.com plugin 1.1 and previous versions for CS-Cart allows remote malicious users to insert arbitrary information into the database (via action=shipnotify) because access to this endpoint is completely unchecked. The attacker must guess an order number.
Vulnerable Product | Search on Vulmon | Subscribe to Product |
---|---|---|
shipstation shipstation |