Lucene search

K
nvd[email protected]NVD:CVE-2013-5977
HistoryNov 01, 2013 - 3:55 p.m.

CVE-2013-5977

2013-11-0115:55:03
CWE-352
web.nvd.nist.gov

6.8 Medium

CVSS2

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:M/Au:N/C:P/I:P/A:P

0.004 Low

EPSS

Percentile

73.8%

Cross-site request forgery (CSRF) vulnerability in Cart66Product.php in the Cart66 Lite plugin before 1.5.1.15 for WordPress allows remote attackers to hijack the authentication of administrators for requests that (1) create or modify products or conduct cross-site scripting (XSS) attacks via the (2) Product name or (3) Price description field in a product save action via a request to wp-admin/admin.php.

Affected configurations

NVD
Node
cart66cart66_lite_pluginRange1.5.1.14-wordpress
OR
cart66cart66_lite_pluginMatch1.0.7-wordpress
OR
cart66cart66_lite_pluginMatch1.0.8-wordpress
OR
cart66cart66_lite_pluginMatch1.1-wordpress
OR
cart66cart66_lite_pluginMatch1.1.1-wordpress
OR
cart66cart66_lite_pluginMatch1.1.2-wordpress
OR
cart66cart66_lite_pluginMatch1.1.3-wordpress
OR
cart66cart66_lite_pluginMatch1.1.4-wordpress
OR
cart66cart66_lite_pluginMatch1.1.5-wordpress
OR
cart66cart66_lite_pluginMatch1.1.6-wordpress
OR
cart66cart66_lite_pluginMatch1.3.0-wordpress
OR
cart66cart66_lite_pluginMatch1.4.0-wordpress
OR
cart66cart66_lite_pluginMatch1.4.1-wordpress
OR
cart66cart66_lite_pluginMatch1.4.2-wordpress
OR
cart66cart66_lite_pluginMatch1.4.4-wordpress
OR
cart66cart66_lite_pluginMatch1.4.7-wordpress
OR
cart66cart66_lite_pluginMatch1.4.8-wordpress
OR
cart66cart66_lite_pluginMatch1.4.9-wordpress
OR
cart66cart66_lite_pluginMatch1.5.0-wordpress
OR
cart66cart66_lite_pluginMatch1.5.0.1-wordpress
OR
cart66cart66_lite_pluginMatch1.5.0.2-wordpress
OR
cart66cart66_lite_pluginMatch1.5.1-wordpress
OR
cart66cart66_lite_pluginMatch1.5.1.1-wordpress
OR
cart66cart66_lite_pluginMatch1.5.1.2-wordpress
OR
cart66cart66_lite_pluginMatch1.5.1.8-wordpress

6.8 Medium

CVSS2

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:M/Au:N/C:P/I:P/A:P

0.004 Low

EPSS

Percentile

73.8%