Back

HIGH

The ShipStation.com plugin 1.0 for CS-Cart allows remote attackers to obtain sensitive information (via action=export) because a typo results in a successful comparison of a blank password and NULL

Published Mar 28, 2023

Description

The ShipStation.com plugin 1.0 for CS-Cart allows remote attackers to obtain sensitive information (via action=export) because a typo results in a successful comparison of a blank password and NULL.

Affected products

Remediation

No remediation recorded yet.

Weaknesses (0)

No CWE recorded.

References (3)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner mitre
Published Mar 28, 2023
Updated Feb 19, 2025
Reserved Feb 11, 2020
CISA Vulnrichment
Updated Feb 19, 2025
NVD
Status Modified
Modified Jun 17, 2026
Red Hat
Severity n/a
Public date n/a
ENISA EUVD
Assigner mitre
Published Mar 28, 2023
Updated Feb 19, 2025
Exploited since n/a
EUVD-2020-29730