PT-2020-18639 · Ec Cube · Ec-Cube
Published
2020-12-03
·
Updated
2022-05-24
·
CVE-2020-5679
CVSS v3.1
6.1
Medium
| Vector | AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
EC-CUBE versions 3.0.0 through 3.0.18
Description
The issue is related to improper restriction of rendered UI layers or frames, which can lead to clickjacking attacks. If a user accesses a specially crafted page while logged into the administrative page, unintended operations may be conducted.
Recommendations
For versions 3.0.0 through 3.0.18, update to a version later than 3.0.18 to resolve the issue.
As a temporary workaround, consider restricting access to administrative pages or implementing additional security measures to minimize the risk of clickjacking attacks.
Fix
Clickjacking
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Ec-Cube