Vulnerabilities (CVE)

Filtered by vendor Hucart Subscribe
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2020-18477 1 Hucart 1 Hucart 2021-08-27 6.5 MEDIUM 8.8 HIGH
SQL Injection vulnerability in Hucart CMS 5.7.4 via the purchase enquiry field found in the Message con_content field.
CVE-2020-18476 1 Hucart 1 Hucart 2021-08-27 6.5 MEDIUM 8.8 HIGH
SQL Injection vulnerability in Hucart CMS 5.7.4 via the basic information field found in the avatar usd_image field.
CVE-2019-6249 1 Hucart 1 Hucart 2019-01-16 6.8 MEDIUM 8.8 HIGH
An issue was discovered in HuCart v5.7.4. There is a CSRF vulnerability that can add an admin account via /adminsys/index.php?load=admins&act=edit_info&act_type=add.