An issue discovered in CS-Cart MultiVendor 4.16.1 allows attackers to alter arbitrary user account profiles via crafted post request.
The product does not properly manage a user within its environment.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Cs-cart_multivendor | Cs-cart | 4.16.1 (including) | 4.16.1 (including) |