What the vulnerability does
01Description
Cross-Site Request Forgery (CSRF) vulnerability in Ecwid Ecommerce Ecwid Ecommerce Shopping Cart.This issue affects Ecwid Ecommerce Shopping Cart: from n/a through 6.12.4.
CVSS base score
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:L
What the vulnerability does
Cross-Site Request Forgery (CSRF) vulnerability in Ecwid Ecommerce Ecwid Ecommerce Shopping Cart.This issue affects Ecwid Ecommerce Shopping Cart: from n/a through 6.12.4.
Explanation of Vulnerability in Simple Terms
Ecwid Ecommerce Shopping Cart versions up to 6.12.4 are vulnerable to cross-site request forgery (CSRF) attacks. An attacker can craft a malicious webpage that, when visited by a logged-in store administrator, performs unwanted actions on the store without the admin's knowledge or consent. The attack requires the victim to visit the attacker's page while authenticated to Ecwid.
What an attacker can do
Perform unwanted actions on an Ecwid store (modify settings, create orders, change products) on behalf of a logged-in administrator.
Potential impact on your site
A store admin's account can be used to make unauthorized changes to products, settings, or orders without their knowledge.
Conditions required to exploit
The store administrator must be logged into Ecwid and visit a malicious webpage controlled by the attacker.
Key dates
External resources
Related vulnerabilities