VYPR
Critical severity9.8NVD Advisory· Published Nov 23, 2018· Updated Jun 17, 2026

CVE-2018-19468

CVE-2018-19468

Description

HuCart 5.7.4 has SQL injection in get_ip() in system/class/helper_class.php via the X-Forwarded-For HTTP header to the user/index.php?load=login&act=act_login URI.

Affected products

2
  • HuCart/HuCart2 versions
    cpe:2.3:a:hucart:hucart:5.7.4:*:*:*:*:*:*:*+ 1 more
    • cpe:2.3:a:hucart:hucart:5.7.4:*:*:*:*:*:*:*
    • (no CPE)range: =5.7.4

Patches

Vulnerability mechanics

References

1

News mentions

0

No linked articles in our index yet.