The ZipCart module for Drupal is prone to a security-bypass vulnerability.
An attacker can exploit this issue to bypass certain security restrictions and perform unauthorized actions; this may aid in launching further attacks.
ZipCart 6.x versions prior to 6.x-1.4 are vulnerable.
Proof of Concept and Security Exploits
Attackers can exploit this issue through a browser.
Security Solution(s)
Solution: Updates are available; please see the references for more information.