CVE-2010-1542

Multiple cross-site request forgery (CSRF) vulnerabilities in admin/configure.php in DFD Cart 1.198, 1.197, and earlier allow remote attackers to hijack the authentication of administrators for requests that (1) conduct cross-site scripting (XSS) attacks or (2) change unspecified settings.
CSRF
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
6.8 UNKNOWN
NETWORK
MEDIUM
AV:N/AC:M/Au:N/C:P/I:P/A:P
mitreCNA
---
---
CVEADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 33%
VendorProductVersion
dragonfrugaldfd_cart
𝑥
≤ 1.198
dragonfrugaldfd_cart
1.1.4
dragonfrugaldfd_cart
1.1.5
dragonfrugaldfd_cart
1.1.6
dragonfrugaldfd_cart
1.1.7
dragonfrugaldfd_cart
1.1.8
dragonfrugaldfd_cart
1.192
dragonfrugaldfd_cart
1.193
dragonfrugaldfd_cart
1.194
dragonfrugaldfd_cart
1.195
dragonfrugaldfd_cart
1.196
dragonfrugaldfd_cart
1.197
𝑥
= Vulnerable software versions