CVE-2023-26689

CVSS 3.1 Score 9.8 of 10 (high)

Details

Published Sep 25, 2024
Updated: Sep 26, 2024
CWE ID 286

Summary

CVE-2023-26689 is a vulnerability affecting CS-Cart MultiVendor version 4.16.1. This issue enables attackers to manipulate user account profiles through carefully crafted post requests. An attacker could exploit this vulnerability to alter sensitive user information, including email addresses, passwords, and other account details. This could potentially lead to unauthorized access to user accounts or phishing attacks. It is crucial that CS-Cart MultiVendor users update to a patched version as soon as possible to mitigate this risk.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share

Affected Products

  • CS-Cart Multi-Vendor

Affected Vendors

  • CS-Cart