PT-2014-3854 · Ec Cube · Ec-Cube+1
Tsuyoshi Nagakawa
·
Published
2014-01-22
·
Updated
2024-07-03
·
CVE-2014-0808
CVSS v3.1
9.1
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N |
Name of the Vulnerable Software and Affected Versions
EC-CUBE versions 2.11.0 through 2.12.2
EC-Orange systems deployed before June 29th, 2015
Description
An issue exists where a user-controlled key can be used to bypass authorization. This can be exploited by sending a crafted HTTP request, potentially allowing a user of the affected shopping website to obtain other users' information.
Recommendations
For EC-CUBE versions 2.11.0 through 2.12.2, update to a version outside of this range to resolve the issue.
For EC-Orange systems deployed before June 29th, 2015, ensure deployment after this date to mitigate the risk.
As a temporary workaround, consider restricting access to sensitive user information until a patch is available.
Fix
IDOR
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Ec-Cube
Ec-Orange