CVE-2018-25435 PUBLISHED

ZeusCart 4.0 Deactivate Customer Accounts CSRF

Assigner: VulnCheck
Reserved: 01.06.2026 Published: 01.06.2026 Updated: 02.06.2026

ZeusCart 4.0 contains a cross-site request forgery vulnerability that allows attackers to perform unauthorized actions on behalf of victims by crafting malicious requests. Attackers can deactivate customer accounts via the admin interface by tricking users into visiting attacker-controlled pages that submit requests to the regstatus endpoint with action=deny parameters.

Metrics

CVSS Vector: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:L/SI:L/SA:L
CVSS Score: 6.9

Product Status

Vendor zeuscart
Product ZeusCart
Versions
  • Version 4.0 is affected

Credits

  • mqt finder

References

Problem Types

  • Cross-Site Request Forgery (CSRF) CWE