cs.com
http://cs.com/ CVE-2025-50850
HIGH
Record summary
CVE-2025-50850 has a selected CVSS score of 8.6 (high).
Description
An issue was discovered in CS Cart 4.18.3 allows the vendor login functionality lacks essential security controls such as CAPTCHA verification and rate limiting. This allows an attacker to systematically attempt various combinations of usernames and passwords (brute-force attack) to gain unauthorized access to vendor accounts. The absence of any blocking mechanism makes the login endpoint susceptible to automated attacks.
Description source: CVE List
Exploitation context
CISA SSVC decision
ExploitationPoC
AutomatableNo
Technical impactPartial
CISA Coordinator · SSVC 2.0.3 · Evaluated Jul 31, 2025 · Source: CVE List
References
3github.com
https://github.com/hackerwahab/CS-Cart-Vulns/blob/main/CVE-2025-50850.md nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2025-50850