EC-CUBE vulnerable to authorization bypass
Moderate severity
GitHub Reviewed
Published
May 17, 2022
to the GitHub Advisory Database
•
Updated Jun 11, 2024
Description
Published by the National Vulnerability Database
Jan 22, 2014
Published to the GitHub Advisory Database
May 17, 2022
Reviewed
Jun 11, 2024
Last updated
Jun 11, 2024
Authorization bypass through user-controlled key issue exists in EC-CUBE 2.11.0 through 2.12.2 and EC-Orange systems deployed before June 29th, 2015. If this vulnerability is exploited, a user of the affected shopping website may obtain other users' information by sending a crafted HTTP request.
References