
2015 Sep 14
ZeusCart 4.0: CSRF
ZeusCart 4.0 does not have CSRF protection. Because of this, it is for example possible to add additional admin accounts. This issue has not been fixed.
ZeusCart 4.0 does not have CSRF protection. Because of this, it is for example possible to add additional admin accounts. This issue has not been fixed.
There is an arbitrary file upload vulnerability in the admin area of ZeusCart 4.0. This issue has not been fixed.
There are multiple SQL Injection vulnerabilities in ZeusCart 4.0. This issue has not been fixed.
There is an XSS vulnerability in ZeusCart 4.0. This issue has not been fixed.