---
id: CVE-2018-25435
title: >-
  ZeusCart 4.0 contains a cross-site request forgery vulnerability that allows
  attackers to perform unauthorized actions on behalf of victims by crafting
  malicious requests
summary: >-
  ZeusCart 4.0 contains a cross-site request forgery vulnerability that allows
  attackers to perform unauthorized actions on behalf of victims by crafting
  malicious requests. Attackers can deactivate customer accounts via the admin
  interfac…
severity: medium
cvss: 5.3
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N'
cwe:
  - CWE-352
published: '2026-06-01'
updated: '2026-10-06'
sourceUpdated: '2026-10-06T22:10:00.247'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2018-25435'
references:
  - url: 'http://http://www.zeuscart.com/'
    label: disclosure@vulncheck.com
  - url: 'https://www.exploit-db.com/exploits/46027'
    label: disclosure@vulncheck.com
  - url: >-
      https://www.vulncheck.com/advisories/zeuscart-deactivate-customer-accounts-csrf
    label: disclosure@vulncheck.com
tags:
  - nvd
epss: 0.00156
epssPercentile: 0.04185
ingestedAt: '2026-10-06T22:23:15.930Z'
---

## Overview

ZeusCart 4.0 contains a cross-site request forgery vulnerability that allows attackers to perform unauthorized actions on behalf of victims by crafting malicious requests. Attackers can deactivate customer accounts via the admin interface by tricking users into visiting attacker-controlled pages that submit requests to the regstatus endpoint with action=deny parameters.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
