CVE-2017-15673: Cs-Cart
High severity, CVSS 7.2. EPSS: 1.9% chance of exploitation in the next 30 days.
The files function in the administration section in CS-Cart 4.6.2 and earlier allows attackers to execute arbitrary PHP code via vectors involving a custom page.
Affected products
- Cs-Cart Cs-Cart: up to and including 4.6.2
Published 2017-11-28. Last modified 2026-06-17.