5.1
CVSSv2

CVE-2015-5665

Published: 27/10/2015 Updated: 28/10/2015
CVSS v2 Base Score: 5.1 | Impact Score: 6.4 | Exploitability Score: 4.9
VMScore: 454
Vector: AV:N/AC:H/Au:N/C:P/I:P/A:P

Vulnerability Summary

Cross-site request forgery (CSRF) vulnerability in LOCKON EC-CUBE 2.11.0 up to and including 2.13.3 allows remote malicious users to hijack the authentication of arbitrary users for requests that write to PHP scripts, related to the doValidToken function.

Vulnerable Product Search on Vulmon Subscribe to Product

lockon ec-cube 2.11.0

lockon ec-cube 2.11.1

lockon ec-cube 2.12.1

lockon ec-cube 2.12.0

lockon ec-cube 2.12.2

lockon ec-cube 2.12.3

lockon ec-cube 2.11.3

lockon ec-cube 2.11.5

lockon ec-cube 2.12.5

lockon ec-cube 2.13.0

lockon ec-cube 2.13.2

lockon ec-cube 2.11.2

lockon ec-cube 2.11.4

lockon ec-cube 2.12.6

lockon ec-cube 2.13.1