Security Advisory

CVE-2013-0118

CVE vulnerability detail - eXtreme Datacenter Security Operations

Published 2013-02-24 11:00:00
Last updated 2024-09-17 02:51:28
Assigner certcc
CVSS score not scored
State PUBLISHED

Description

CS-Cart before 3.0.6, when PayPal Standard Payments is configured, allows remote attackers to set the payment recipient via a modified value of the merchant's e-mail address, as demonstrated by setting the recipient to one's self.