ShadowTrackr

Search the CVE vulnerability database

Look up vulnerabilities by software, product or CVE number.

1 result for “CVE-2020-9009”

CVEPublishedCVSSShadowTrackr CVSSSummary
CVE:
CVE-2020-9009
Published
2023-04-11
CVSS:
3.7
ShadowTrackr CVSS:
1.7
Summary:
The ShipStation.com plugin 1.1 and earlier for CS-Cart allows remote attackers to insert arbitrary information into the database (via action=shipnotify) because access to this endpoint is completely unchecked. The attacker must guess an order number.