jer's blog

Minimum requirements for CVE-2020-8889

Minimum requirements:

SA: ShipStation plugin for CS-Cart - incorrect access control, compromised database integrity

Description:

The ShipStation plugin for CS-Cart version v1.0.10 and earlier allows remote attackers to insert arbitrary information into the database (via action=shipnotify) because access to this endpoint is completely unchecked.

Additional information:

SA: Shipstation plugin for CS-Cart - Incorrect Access Control

Description:

The ShipStation.com plugin 1.0 for CS-Cart allows remote attackers to obtain sensitive information (via action=export) because a typo results in a successful comparison of a blank password and NULL.

Additional information:

Subscribe to RSS - jer's blog