CVE-2016-4828: Medium severity collne welcart vulnerability
Published Jun 25, 2016
·Updated
The Collne Welcart e-Commerce plugin before 1.8.3 for WordPress mishandles sessions, which allows remote attackers to obtain access by leveraging knowledge of the e-mail address associated with an account.
Affected Software
2 affected components
Collne Welcart E-commerce Wordpress<1.8.3
Welcart Welcart e-Commerce WordPress<1.8.3
Event History
Jun 25, 2016
CVE Published
via MITRE·09:00 PM
Data Sourced
via MITRE·09:00 PM
Description
Data Sourced
via NVD·09:59 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2016-4828?
CVE-2016-4828 has a medium severity rating due to the potential for unauthorized access to user accounts.
2
How do I fix CVE-2016-4828?
To fix CVE-2016-4828, update the Welcart e-Commerce plugin to version 1.8.3 or later.
3
Who is affected by CVE-2016-4828?
Users of the Welcart e-Commerce plugin for WordPress prior to version 1.8.3 are affected by CVE-2016-4828.
4
What kind of access does CVE-2016-4828 allow for attackers?
CVE-2016-4828 allows remote attackers to gain access to user accounts by exploiting session mismanagement.
5
What is the main cause of CVE-2016-4828?
The main cause of CVE-2016-4828 is the mishandling of sessions in the Welcart e-Commerce plugin.