To give you more time to protect your store, we are not disclosing the technical details. Suffice it to say that we advise everyone who uses a version from 4.0.1 up to 4.7.1 (including 4.7.1 SP1) to take one of the following measures as soon as possible:
Upgrade to CS-Cart or Multi-Vendor 4.7.1 SP2. This version contains the fixes for all the security issues that we are aware of. It is already available in the Upgrade Center in the Administration panel of your store. Please note that to see 4.7.1 SP2 in the Upgrade Center, you’ll first need to install the upgrades that came before 4.7.1 SP2, if you haven’t done that already.
For those who can’t upgrade to the latest version, we have prepared a free add-on that addresses the problems. We think that installing an add-on is much more convenient for a store owner than changing lines of code in various files manually. To get the add-on:
- Sign in to Help Desk before you can download the add-on. Enter the email and password of your Help Desk account. Alternatively, use the Forgot your password? link on that page to sign in without using a password.
- Once you sign in to Help Desk, go to the File area. Scroll down to find the Updates folder. Click on that folder to open it.
- Find the security_fixes_4xx_addon.zip file. Download it by clicking the icon on the right.
- The archive with the add-on will be downloaded to your computer. Install the add-on from the archive as described in the documentation.