CVE Vulnerabilities

CVE-2017-2143

Direct Request ('Forced Browsing')

Published: Apr 28, 2017 | Modified: Oct 03, 2019
CVSS 3.x
5.3
MEDIUM
Source:
NVD
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
CVSS 2.x
5 MEDIUM
AV:N/AC:L/Au:N/C:N/I:P/A:N
RedHat/V2
RedHat/V3
Ubuntu

CS-Cart Japanese Edition v4.3.10-jp-1 and earlier, CS-Cart Multivendor Japanese Edition v4.3.10-jp-1 and earlier allows remote attackers to bypass access restriction to create a request to return a customer purchased item via rma.post.php.

Weakness

The web application does not adequately enforce appropriate authorization on all restricted URLs, scripts, or files.

Affected Software

Name Vendor Start Version End Version
Cs-cart_japanese_edition Frogman_office_inc 4.3.10-jp-1 (including) 4.3.10-jp-1 (including)
Cs-cart_multivendor_japanese_edition Frogman_office_inc 4.3.10-jp-1 (including) 4.3.10-jp-1 (including)

Potential Mitigations

References