PT-2017-6558 · Epicor · Epicor Crs Retail Store
Published
2017-09-06
·
Updated
2018-10-09
·
CVE-2015-2210
CVSS v2.0
7.2
High
| Vector | AV:L/AC:L/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
Epicor CRS Retail Store versions prior to 3.2.03.01.008
Description
The issue allows local users to execute arbitrary code by injecting Javascript into the help window source, enabling the creation of a button that spawns a command shell.
Recommendations
For versions prior to 3.2.03.01.008, update to version 3.2.03.01.008 or later to resolve the issue.
Fix
Command Injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Epicor Crs Retail Store