ZeusCart 4.0 contains a cross-site request forgery vulnerability that allows attackers to perform unauthorized actions on behalf of victims by crafting malicious requests. Attackers can deactivate customer accounts via the admin interface by tricking users into visiting attacker-controlled pages that submit requests to the regstatus endpoint with action=deny parameters.
Metrics
Affected Vendors & Products
References
History
Mon, 01 Jun 2026 21:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | ZeusCart 4.0 contains a cross-site request forgery vulnerability that allows attackers to perform unauthorized actions on behalf of victims by crafting malicious requests. Attackers can deactivate customer accounts via the admin interface by tricking users into visiting attacker-controlled pages that submit requests to the regstatus endpoint with action=deny parameters. | |
| Title | ZeusCart 4.0 Deactivate Customer Accounts CSRF | |
| First Time appeared |
Zeuscart
Zeuscart zeuscart |
|
| Weaknesses | CWE-352 | |
| CPEs | cpe:2.3:a:zeuscart:zeuscart:4.0:*:*:*:*:*:*:* | |
| Vendors & Products |
Zeuscart
Zeuscart zeuscart |
|
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-06-01T21:00:24.645Z
Reserved: 2026-06-01T12:03:03.490Z
Link: CVE-2018-25435
No data.
Status : Received
Published: 2026-06-01T22:16:17.007
Modified: 2026-06-01T22:16:17.007
Link: CVE-2018-25435
No data.
OpenCVE Enrichment
Updated: 2026-06-01T23:30:12Z