Cross-Site Request Forgery Vulnerability in EC Cloud E-Commerce System
CVE-2020-21139
6.5MEDIUM
Key Information:
- Vendor
- CVE Published:
- 4 November 2021
What is CVE-2020-21139?
The EC Cloud E-Commerce System v1.3 has been identified with a Cross-Site Request Forgery vulnerability, which enables attackers to create admin accounts without proper authorization. By exploiting this weakness through the /admin.html?do=user&act=add endpoint, malicious users can gain elevated privileges within the application, posing significant risks to the integrity and security of the system. This vulnerability underscores the importance of implementing robust protection mechanisms against CSRF attacks to safeguard sensitive application functions.
