PT-2021-14286 · Ec Cube · Ec-Cube

Published

2021-11-24

·

Updated

2022-05-24

·

CVE-2021-20842

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N
Name of the Vulnerable Software and Affected Versions: EC-CUBE 2 series versions 2.11.0 through 2.17.1
Description: A cross-site request forgery (CSRF) issue allows a remote attacker to hijack the authentication of an Administrator and potentially delete the Administrator account via a specially crafted web page.
Recommendations: For versions 2.11.0 through 2.17.1, consider implementing CSRF token validation to prevent unauthorized requests. As a temporary workaround, restrict access to Administrator functions until a patch is available. Avoid using the affected EC-CUBE 2 series versions until the issue is resolved.

Exploit

Fix

CSRF

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2021-20842
GHSA-M9HV-QMQH-33QH

Affected Products

Ec-Cube