Home
Home
Trends
Trends
Vulnerabilities
Vulnerabilities
News
News
Researchers
Researchers
Why dbugs?
Why dbugs?
Settings

Allenchen

#30807of 56,326
8.8Total CVSS
Vulnerabilities · 1
PT-2019-18054
8.8
2019-01-13
Hucart · Hucart · CVE-2019-6249
**Name of the Vulnerable Software and Affected Versions** HuCart version 5.7.4 **Description** A CSRF issue allows adding an admin account via the /adminsys/index.php?load=admins&act=edit info&act type=add API endpoint. **Recommendations** For HuCart version 5.7.4, as a temporary workaround, consider restricting access to the /adminsys/index.php?load=admins&act=edit info&act type=add API endpoint until a patch is available. At the moment, there is no information about a newer version that contains a fix for this issue.