CVE-2015-5665 Information

Description

Cross-site request forgery (CSRF) vulnerability in LOCKON EC-CUBE 2.11.0 through 2.13.3 allows remote attackers to hijack the authentication of arbitrary users for requests that write to PHP scripts related to the doValidToken function.

Reference

http://jvn.jp/en/jp/JVN97278546/index.html http://jvndb.jvn.jp/jvndb/JVNDB-2015-000166 http://www.ec-cube.net/info/weakness/weakness.php?id=63 https://www.ec-cube.net/info/weakness/201510_01/

Share on: