We use these services and cookies to improve your user experience. You may opt out if you wish, however, this may limit some features on this site.
Please see our statement on Data Privacy.
Authorization bypass through user-controlled key issue exists in EC-CUBE 2.11.0 through 2.12.2 and EC-Orange systems deployed before June 29th, 2015. If this vulnerability is exploited, a user of the affected shopping website may obtain other users' information by sending a crafted HTTP request.
Reserved 2014-01-06 | Published 2014-01-22 | Updated 2024-08-06 | Assigner jpcertAuthorization Bypass Through User-Controlled Key
www.ec-cube.net/info/weakness/weakness.php?id=57
jvndb.jvn.jp/jvndb/JVNDB-2014-000006
jvndb.jvn.jp/jvndb/JVNDB-2024-000054
Support options