Input Validation Flaw in EC-CUBE and GMO-PG Payment Modules
CVE-2018-0658
What is CVE-2018-0658?
An input validation issue found in certain versions of the EC-CUBE and GMO-PG Payment Modules allows an attacker with administrative rights to execute arbitrary PHP code on the server. This vulnerability can be exploited through unspecified vectors, potentially compromising the security of the entire system. It is crucial for users of these payment modules to ensure they are using the latest versions to mitigate the risks associated with this issue.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
EC-CUBE Payment Module and GMO-PG Payment Module (PG Multi-Payment Service) for EC-CUBE (EC-CUBE Payment Module (2.12) version 3.5.23 and earlier, EC-CUBE Payment Module (2.11) version 2.3.17 and earlier, GMO-PG Payment Module (PG Multi-Payment Service) (2.12) version 3.5.23 and earlier, and GMO-PG Payment Module (PG Multi-Payment Service) (2.11) version 2.3.17 and earlier)
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved
