Executive brief
A security flaw in the CS-Cart e-commerce platform allows users to upload malicious HTML files that the server then displays as legitimate pages. Because these files are hosted on the store's own trusted domain, attackers can use them to create highly convincing fake login forms to steal customer credentials or run unauthorized scripts in a user's browser. This could lead to account takeovers and significant damage to the store's reputation and customer trust.
Technical details
An unrestricted file upload vulnerability exists in CS-Cart 4.18.3 within the File Manager component (vendor.php). The application fails to properly restrict or sanitize the upload of .html files, which are subsequently served by the web server with headers that allow direct browser rendering. A remote attacker can upload a crafted HTML file containing malicious JavaScript or phishing forms. When a victim visits the URL of the uploaded file, the script executes in the context of the trusted domain (Stored XSS), potentially allowing for session hijacking, data theft, or credential harvesting. Mitigation involves implementing server-side file extension filtering and using 'Content-Disposition: attachment' headers for user-uploaded content.
Affected products
- CS-Cart CS-Cart 4.18.3
Timeline
- 2025-07-31: advisory: NVD Published Date
- 2025-07-31: disclosed: Initial disclosure by security researcher