CyberRota Analysis
AI analysis pending.
CVE
CVE-2020-9009
Severity
LOW
CVSS
3.7
EPSS
0.63%
Original NVD Description
The ShipStation.com plugin 1.1 and earlier for CS-Cart allows remote attackers to insert arbitrary information into the database (via action=shipnotify) because access to this endpoint is completely unchecked. The attacker must guess an order number.