Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
The ShipStation.com plugin 1.1 and earlier for CS-Cart allows remote attackers to insert arbitrary information into the database (via action=shipnotify) because access to this endpoint is completely unchecked. The attacker must guess an order number.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
ShipStation 安全漏洞
Vulnerability Description
ShipStation是ShipStation的一款电子商务零售订单承运处理和运送软件。 ShipStation 1.1及之前版本存在安全漏洞,该漏洞源于对端点的访问未经检查,允许远程攻击者将任意信息插入数据库。
CVSS Information
N/A
Vulnerability Type
N/A