[Japanese]

JVNDB-2011-000029

EC-CUBE vulnerable to cross-site request forgery

Overview

EC-CUBE provided by LOCKON CO.,LTD. contains a cross-site request forgery vulnerability.

EC-CUBE provided by LOCKON CO.,LTD. is an open source system for creating shopping websites. EC-CUBE contains a cross-site request forgery vulnerability.

Masako Oono reported this vulnerability to IPA.
JPCERT/CC coordinated with the developer under Information Security Early Warning Partnership.
CVSS Severity (What is CVSS?)

Base Metrics: 2.6 (Low) [IPA Score]
  • Access Vector: Network
  • Access Complexity: High
  • Authentication: None
  • Confidentiality Impact: None
  • Integrity Impact: Partial
  • Availability Impact: None

Affected Products


LOCKON CO.,LTD
  • EC-CUBE versions prior to 2.11.0

Impact

If a user views a malicious page while logged in, information stored within EC-CUBE may be altered.
Solution

[Update the Software]
Apply the latest update provided by the developer.
Vendor Information

LOCKON CO.,LTD
CWE (What is CWE?)

  1. Cross-Site Request Forgery(CWE-352) [IPA Evaluation]
CVE (What is CVE?)

  1. CVE-2011-1325
References

  1. JVN : JVN#37878530
  2. National Vulnerability Database (NVD) : CVE-2011-1325
  3. Secunia Advisory : SA44487
  4. OPEN SOURCE VULNERABILITY DATABASE (OSVDB) : 72239
Revision History

[2011/05/11]
  Web page published