Known Vulnerabilities for products from Hucart
Listed below are 6 of the newest known vulnerabilities associated with the vendor "Hucart".
These CVEs are retrieved based on exact matches on listed vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed vendor information are still displayed.
Data on known vulnerable products is also displayed based on information from known CPEs, each product links to its respective vulnerability page.
Known Vulnerabilities
| CVE | Shortened Description | Severity | Publish Date | Last Modified |
|---|---|---|---|---|
| CVE-2020-18477 json | SQL Injection vulnerability in Hucart CMS 5.7.4 via the purchase enquiry field found in the Message con_content field. | 8.8 - HIGH | 2021-08-26 | 2021-08-27 |
| CVE-2020-18476 json | SQL Injection vulnerability in Hucart CMS 5.7.4 via the basic information field found in the avatar usd_image field. | 8.8 - HIGH | 2021-08-26 | 2021-08-27 |
| CVE-2020-18475 json | Cross Site Scripting (XSS) vulnerabilty exists in Hucart CMS 5.7.4 is via the mes_title field. The first user inserts a malic... | 5.4 - MEDIUM | 2021-08-26 | 2021-08-27 |
| CVE-2020-18158 json | Cross Site Scripting (XSS) vulnerability in HuCart 5.7.4 via nickname in index.php. | 5.4 - MEDIUM | 2021-07-30 | 2021-08-03 |
| CVE-2019-6249 json | An issue was discovered in HuCart v5.7.4. There is a CSRF vulnerability that can add an admin account via /adminsys/index.php... | 8.8 - HIGH | 2019-01-13 | 2019-01-16 |
| CVE-2018-19468 json | HuCart 5.7.4 has SQL injection in get_ip() in system/class/helper_class.php via the X-Forwarded-For HTTP header to the user/i... | 9.8 - CRITICAL | 2018-11-23 | 2018-12-19 |
Known software with vulnerabilities from Hucart
| Type | Vendor | Product | Version |
|---|---|---|---|
| Application | Hucart | Hucart | 5.7.4 |