Описание
CubeCart is an ecommerce software solution. Prior to version 6.5.11, a logic flaw exists in the newsletter subscription endpoint that allows an attacker to unsubscribe any user without their consent. By changing the value of the force_unsubscribe parameter in the POST request to 1, an attacker can force the removal of any valid subscriber’s email address. This issue has been patched in version 6.5.11.
Ссылки
- Patch
- Patch
- Patch
- ExploitVendor Advisory
- ExploitVendor Advisory
Уязвимые конфигурации
Конфигурация 1Версия до 6.5.11 (исключая)
cpe:2.3:a:cubecart:cubecart:*:*:*:*:*:*:*:*
EPSS
Процентиль: 25%
0.00089
Низкий
6.5 Medium
CVSS3
Дефекты
CWE-862
EPSS
Процентиль: 25%
0.00089
Низкий
6.5 Medium
CVSS3
Дефекты
CWE-862