Cross-Site Request Forgery Vulnerability in EC Cloud E-Commerce System
CVE-2020-21139

6.5MEDIUM

What is CVE-2020-21139?

The EC Cloud E-Commerce System v1.3 has been identified with a Cross-Site Request Forgery vulnerability, which enables attackers to create admin accounts without proper authorization. By exploiting this weakness through the /admin.html?do=user&act=add endpoint, malicious users can gain elevated privileges within the application, posing significant risks to the integrity and security of the system. This vulnerability underscores the importance of implementing robust protection mechanisms against CSRF attacks to safeguard sensitive application functions.

References

CVSS V3.1

Score:
6.5
Severity:
MEDIUM
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.