CVE-2023-38130: CSRF
Published Nov 17, 2023
·Updated
Cross-site request forgery (CSRF) vulnerability in CubeCart prior to 6.5.3 allows a remote unauthenticated attacker to delete data in the system.
Affected Software
1 affected component
Cubecart CubeCart<6.5.3
Remediation
Patch Available
Event History
Nov 17, 2023
CVE Published
04:37 AM
Data Sourced
04:37 AM
DescriptionWeakness
Frequently Asked Questions
1
What is the vulnerability ID for this CubeCart vulnerability?
The vulnerability ID for this CubeCart vulnerability is CVE-2023-38130.
2
What is the severity of CVE-2023-38130?
The severity of CVE-2023-38130 is high with a CVSS score of 8.1.
3
How does the CSRF vulnerability in CubeCart prior to 6.5.3 work?
The CSRF vulnerability in CubeCart prior to 6.5.3 allows a remote unauthenticated attacker to delete data in the system.
4
Which versions of CubeCart are affected by this vulnerability?
CubeCart versions up to and exclusive of 6.5.3 are affected by this vulnerability.
5
How can I fix the CSRF vulnerability in CubeCart?
To fix the CSRF vulnerability in CubeCart, upgrade to version 6.5.3 or newer.