PT-2021-14233 · Ec Cube · Ec-Cube

Published

2021-07-01

·

Updated

2021-07-08

·

CVE-2021-20778

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions: EC-CUBE version 4.0.6
Description: The issue is related to improper access control, allowing a remote attacker to bypass access restrictions and obtain sensitive information.
Recommendations: For EC-CUBE version 4.0.6, update to a version that addresses the improper access control issue to prevent unauthorized access to sensitive information.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2021-20778

Affected Products

Ec-Cube