PT-2020-18639 · Ec Cube · Ec-Cube

Published

2020-12-03

·

Updated

2022-05-24

·

CVE-2020-5679

CVSS v3.1

6.1

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions EC-CUBE versions 3.0.0 through 3.0.18
Description The issue is related to improper restriction of rendered UI layers or frames, which can lead to clickjacking attacks. If a user accesses a specially crafted page while logged into the administrative page, unintended operations may be conducted.
Recommendations For versions 3.0.0 through 3.0.18, update to a version later than 3.0.18 to resolve the issue. As a temporary workaround, consider restricting access to administrative pages or implementing additional security measures to minimize the risk of clickjacking attacks.

Fix

Clickjacking

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2020-5679
GHSA-RWH8-H525-4JVJ

Affected Products

Ec-Cube