Cross-Site Request Forgery Vulnerability in EC-CUBE by EC-CUBE Co.
CVE-2021-20842

6.5MEDIUM

Key Information:

Vendor
CVE Published:
24 November 2021

What is CVE-2021-20842?

A cross-site request forgery (CSRF) vulnerability exists in the EC-CUBE 2 series, specifically from versions 2.11.0 to 2.17.1. This flaw allows an attacker to create a malicious web page that, when visited by an administrator, could hijack their session and execute actions on their behalf. The possible malicious actions include the unauthorized deletion of an administrator account, potentially jeopardizing the security and integrity of the EC-CUBE installation. Users are advised to apply security patches and mitigate risks associated with this vulnerability.

Affected Version(s)

EC-CUBE 2 series 2.11.0 to 2.17.1

References

CVSS V3.1

Score:
6.5
Severity:
MEDIUM
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.