← Vulnerability feed

Vulnerability record · CVE-2017-2138 · published 2 August 2017

CVE-2017-2138: Cs-cart cross-site request forgery vulnerability

Cs Cart · Cs Cart

Cross-site request forgery (CSRF) vulnerability in CS-Cart Japanese Edition v4.3.10 and earlier (excluding v2 and v3), CS-Cart Multivendor Japanese Edition v4.3.10 and earlier (excluding v2 and v3) allows remote attackers to hijack the authentication of administrators via unspecified vectors.

8.8 CVSS 3.0 High EPSS 1.0% · top 37.7% CWE-352 · Cross-site request forgery
8.8CVSS 3.0 base score, v2 6.8
1.0%EPSS exploitation probability, 30 days
NoNot in CISA KEV
2Affected product versions listed by NVD
4References
17 Jun 2026Last modified by NVD

Description

Cross-site request forgery (CSRF) vulnerability in CS-Cart Japanese Edition v4.3.10 and earlier (excluding v2 and v3), CS-Cart Multivendor Japanese Edition v4.3.10 and earlier (excluding v2 and v3) allows remote attackers to hijack the authentication of administrators via unspecified vectors.

CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

Affected products

2 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2017-2138 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2023-26686Cs-cart multivendor unrestricted file upload vulnerabilityFile Upload vulnerability in CS-Cart MultiVendor 4.16.1 allows remote attackers to run arbitrary code via the image upload feature when customizing a…EPSS 0.71%9.8CVE-2023-26689Cs-cart multivendor vulnerabilityAn issue discovered in CS-Cart MultiVendor 4.16.1 allows attackers to alter arbitrary user account profiles via crafted post request.EPSS 0.62%8.8CVE-2023-26687Cs-cart multivendor path traversal vulnerabilityDirectory Traversal vulnerability in CS-Cart MultiVendor 4.16.1 allows remote attackers to obtain sensitive information via the product_data paramete…EPSS 1.3%8.8CVE-2023-26690Cs-cart multivendor unrestricted file upload vulnerabilityFile Upload vulnerability in CS-Cart MultiVendor 4.16.1 allows remote attackers to run arbitrary code via File Manager/Editor component in the vendor…EPSS 0.68%8.8CVE-2016-4862Cs-cart improper input validation vulnerabilityTwigmo bundled with CS-Cart 4.3.9 and earlier and Twigmo bundled with CS-Cart Multi-Vendor 4.3.9 and earlier allow remote authenticated users to exec…EPSS 2.1%8.6CVE-2025-50850Cs-cart improper access control vulnerabilityAn issue was discovered in CS Cart 4.18.3 allows the vendor login functionality lacks essential security controls such as CAPTCHA verification and ra…EPSS 0.23%7.5CVE-2009-4891Cs-cart sql injection vulnerabilitySQL injection vulnerability in index.php in CS-Cart 2.0.0 Beta 3 allows remote attackers to execute arbitrary SQL commands via the product_id paramet…EPSS 1.1%7.5CVE-2008-6394Cs-cart sql injection vulnerabilitySQL injection vulnerability in core/user.php in CS-Cart 1.3.5 and earlier allows remote attackers to execute arbitrary SQL commands via the cs_cookie…EPSS 1.2%

Source: NIST National Vulnerability Database (record CVE-2017-2138), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.