peter bassill · operator
$ cve CVE-2011-0503 JSON

CVE-2011-0503 EXPLOIT

6.8
MEDIUM · CVSS 2.0 · EPSS 2.1% (pctl 81)

Patch early

A public exploit exists.

Description

Cross-site request forgery (CSRF) vulnerability in VaM Shop 1.6, 1.6.1, and probably earlier versions allows remote attackers to hijack the authentication of administrators for requests that (1) change user status via admin/customers.php or (2) change user permissions via admin/accounting.php. NOTE: some of these details are obtained from third party information.

Scoring

CVSS6.8 (MEDIUM, v2.0)
VectorAV:N/AC:M/Au:N/C:P/I:P/A:P
EPSS2.11% — more likely to be exploited than 81% of all CVEs
WeaknessCWE-352
On CISA KEVno
Public exploityes
Published2011-01-20
Last modified2026-06-16

Affected (1)

VendorProduct
vamsoftvam shop

Public exploits

SourceTitleDate
exploit-dbvam shop 1.6 - Multiple Vulnerabilities2011-01-11

References

→ the Explorer  ·  watch your stack  ·  NVD