CVE-2015-2701
CS-Cart 4.2.4 - Cross-Site Request Forgery via Password Change Request
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2015-2701. PoCs published by Luis Santana.
AI-analyzed exploit summary This is a CSRF (Cross-Site Request Forgery) exploit for CS-Cart 4.2.4 that allows an attacker to change a user's password by tricking them into visiting a malicious webpage. The exploit submits a form with predefined values to the target endpoint without requiring user interaction.
Description
Cross-site request forgery (CSRF) vulnerability in CS-Cart 4.2.4 allows remote attackers to hijack the authentication of users for requests that change a user password via a request to profiles-update/.
Exploits (1)
This is a CSRF (Cross-Site Request Forgery) exploit for CS-Cart 4.2.4 that allows an attacker to change a user's password by tricking them into visiting a malicious webpage. The exploit submits a form with predefined values to the target endpoint without requiring user interaction.