« Volver al listado

CVE-2013-0118

Estado: ModificadaMedia (5)—

CS-Cart before 3.0.6, when PayPal Standard Payments is configured, allows remote attackers to set the payment recipient via a modified value of the merchant's e-mail address, as demonstrated by setting the recipient to one's self.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2013-0118",
  "cveTags": [],
  "metrics": {
    "cvssMetricV2": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "version": "2.0",
          "baseScore": 5,
          "accessVector": "NETWORK",
          "vectorString": "AV:N/AC:L/Au:N/C:N/I:P/A:N",
          "authentication": "NONE",
          "integrityImpact": "PARTIAL",
          "accessComplexity": "LOW",
          "availabilityImpact": "NONE",
          "confidentialityImpact": "NONE"
        },
        "acInsufInfo": false,
        "impactScore": 2.9,
        "baseSeverity": "MEDIUM",
        "obtainAllPrivilege": false,
        "exploitabilityScore": 10,
        "obtainUserPrivilege": false,
        "obtainOtherPrivilege": false,
        "userInteractionRequired": false
      }
    ]
  },
  "affected": [
    {
      "source": "cret@cert.org",
      "affectedData": [
        {
          "vendor": "n/a",
          "product": "n/a",
          "versions": [
            {
              "status": "affected",
              "version": "n/a"
            }
          ]
        }
      ]
    }
  ],
  "published": "2013-02-24T11:48:21.487",
  "references": [
    {
      "url": "http://www.kb.cert.org/vuls/id/583564",
      "tags": [
        "US Government Resource"
      ],
      "source": "cret@cert.org"
    },
    {
      "url": "http://www.kb.cert.org/vuls/id/BLUU-949PQL",
      "source": "cret@cert.org"
    },
    {
      "url": "http://www.kb.cert.org/vuls/id/583564",
      "tags": [
        "US Government Resource"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://www.kb.cert.org/vuls/id/BLUU-949PQL",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Modified",
  "weaknesses": [
    {
      "type": "Primary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "CWE-16"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "CS-Cart before 3.0.6, when PayPal Standard Payments is configured, allows remote attackers to set the payment recipient via a modified value of the merchant's e-mail address, as demonstrated by setting the recipient to one's self."
    },
    {
      "lang": "es",
      "value": "CS-Cart anterior a v3.0.6, cuando está configurado con PayPal Standard Payments, permite a atacantes remotos indicar el receptor del pago a través de un valor en la dirección del correo del comerciante."
    }
  ],
  "lastModified": "2026-06-16T23:48:48.267",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:cs-cart:cs-cart:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "91F91E50-9B37-4CC7-B27C-331739A27351",
              "versionEndIncluding": "3.0.5"
            },
            {
              "criteria": "cpe:2.3:a:cs-cart:cs-cart:3.0:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "52F3E4CE-4A77-42CE-9F57-B5D05CCF05D3"
            },
            {
              "criteria": "cpe:2.3:a:cs-cart:cs-cart:3.0.2:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "4BA204ED-767B-4928-8870-33B25A10F3A4"
            },
            {
              "criteria": "cpe:2.3:a:cs-cart:cs-cart:3.0.3:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "BB2D439E-F3D1-4D3A-90EC-50EE09CAD1A5"
            },
            {
              "criteria": "cpe:2.3:a:cs-cart:cs-cart:3.0.4:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "99F8E1C7-C33F-4BC9-A560-50439233F53E"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "cret@cert.org"
}