Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
CS-Cart before 3.0.6, when PayPal Standard Payments is configured, allows remote attackers to set the payment recipient via a modified value of the merchant's e-mail address, as demonstrated by setting the recipient to one's self.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
CS-Cart 配置错误漏洞
Vulnerability Description
CS-Cart是CS-Cart团队开发的一套基于PHP和MySQL的电子商务软件系统。该系统支持第三方软件扩展、自定义促销策略、产品筛选定义等。 CS-Cart 3.0.6版本中存在漏洞。在已配置了PayPal标准支付的条件下,通过对商家e-mail地址进行修改,远程攻击者可利用该漏洞设定支付收款方,比如将收款人设为自己。
CVSS Information
N/A
Vulnerability Type
N/A