Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Tue, 02 Jun 2026 13:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Mon, 01 Jun 2026 21:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | ZeusCart 4.0 contains a cross-site request forgery vulnerability that allows attackers to perform unauthorized actions on behalf of victims by crafting malicious requests. Attackers can deactivate customer accounts via the admin interface by tricking users into visiting attacker-controlled pages that submit requests to the regstatus endpoint with action=deny parameters. | |
| Title | ZeusCart 4.0 Deactivate Customer Accounts CSRF | |
| First Time appeared |
Zeuscart
Zeuscart zeuscart |
|
| Weaknesses | CWE-352 | |
| CPEs | cpe:2.3:a:zeuscart:zeuscart:4.0:*:*:*:*:*:*:* | |
| Vendors & Products |
Zeuscart
Zeuscart zeuscart |
|
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-06-02T12:28:37.978Z
Reserved: 2026-06-01T12:03:03.490Z
Link: CVE-2018-25435
Updated: 2026-06-02T12:28:15.435Z
Status : Deferred
Published: 2026-06-01T22:16:17.007
Modified: 2026-06-02T14:43:49.920
Link: CVE-2018-25435
No data.
OpenCVE Enrichment
Updated: 2026-06-01T23:30:12Z