PT-2016-4639 · Lockon · Ec-Cube

Published

2016-04-30

·

Updated

2016-11-28

·

CVE-2016-1201

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions LOCKON EC-CUBE versions 3.0.0 through 3.0.9
Description A cross-site request forgery (CSRF) issue allows remote attackers to hijack the authentication of administrators. This can be exploited by tricking administrators into performing unintended actions.
Recommendations For versions 3.0.0 through 3.0.9, update to a version that contains a fix for this issue to prevent CSRF attacks.

Fix

CSRF

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2016-1201

Affected Products

Ec-Cube