Executive brief
Smartshop, an e-commerce website platform, is vulnerable to a security flaw that allows unauthorized changes to user accounts. By tricking a logged-in administrator into visiting a malicious webpage, an attacker can silently change the administrator's email address and password. This could lead to a full takeover of the administrative account and the e-commerce site.
Technical details
A Cross-Site Request Forgery (CSRF) vulnerability exists in Smartshop version 1.0 and earlier within the 'editprofile.php' component. The application fails to implement anti-CSRF tokens or similar validation mechanisms for profile update requests. An attacker can exploit this by hosting a malicious HTML page containing a hidden form that targets the administrative profile update endpoint. If an authenticated administrator visits this page, the browser will automatically submit the form, allowing the attacker to change the administrator's email and password without their knowledge. This vulnerability requires the victim to be authenticated and to interact with a malicious link or site.
Affected products
- Smakosh Smartshop 1.0 and earlier
Timeline
- 2018-06-02: disclosed: Initial exploit published on Exploit-DB
- 2026-05-23: advisory: CVE published and assigned by VulnCheck