An issue was discovered in CS Cart 4.18.3 allows the vendor login functionality lacks essential security controls such as CAPTCHA verification and rate limiting. This allows an attacker to systematically attempt various combinations of usernames and passwords (brute-force attack) to gain unauthorized access to vendor accounts. The absence of any blocking mechanism makes the login endpoint susceptible to automated attacks.
History

Wed, 06 Aug 2025 16:45:00 +0000

Type Values Removed Values Added
CPEs cpe:2.3:a:cs-cart:cs-cart:4.18.3:*:*:*:*:*:*:*

Thu, 31 Jul 2025 20:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-284
CWE-804
Metrics cvssV3_1

{'score': 8.6, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:H'}


Thu, 31 Jul 2025 19:45:00 +0000

Type Values Removed Values Added
First Time appeared Cs-cart
Cs-cart cs-cart
Vendors & Products Cs-cart
Cs-cart cs-cart

Thu, 31 Jul 2025 16:00:00 +0000

Type Values Removed Values Added
Description An issue was discovered in CS Cart 4.18.3 allows the vendor login functionality lacks essential security controls such as CAPTCHA verification and rate limiting. This allows an attacker to systematically attempt various combinations of usernames and passwords (brute-force attack) to gain unauthorized access to vendor accounts. The absence of any blocking mechanism makes the login endpoint susceptible to automated attacks.
References

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published: 2025-07-31T00:00:00.000Z

Updated: 2025-07-31T19:57:19.017Z

Reserved: 2025-06-16T00:00:00.000Z

Link: CVE-2025-50850

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Analyzed

Published: 2025-07-31T16:15:31.163

Modified: 2025-08-06T16:34:48.977

Link: CVE-2025-50850

cve-icon Redhat

No data.