PT-2021-14233 · Ec Cube · Ec-Cube
Published
2021-07-01
·
Updated
2021-07-08
·
CVE-2021-20778
CVSS v3.1
7.5
High
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions:
EC-CUBE version 4.0.6
Description:
The issue is related to improper access control, allowing a remote attacker to bypass access restrictions and obtain sensitive information.
Recommendations:
For EC-CUBE version 4.0.6, update to a version that addresses the improper access control issue to prevent unauthorized access to sensitive information.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Ec-Cube