Vulnerability Description
Improper access control vulnerability in EC-CUBE 4.0.6 (EC-CUBE 4 series) allows a remote attacker to bypass access restriction and obtain sensitive information via unspecified vectors.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Ec-Cube | Ec-Cube | 4.0.6 |
References
- http://jvn.jp/en/jp/JVN57942445/index.htmlThird Party Advisory
- https://jvn.jp/en/jp/JVN57942445/index.htmlThird Party Advisory
- https://www.ec-cube.net/info/weakness/weakness.php?id=80PatchVendor Advisory
- http://jvn.jp/en/jp/JVN57942445/index.htmlThird Party Advisory
- https://jvn.jp/en/jp/JVN57942445/index.htmlThird Party Advisory
- https://www.ec-cube.net/info/weakness/weakness.php?id=80PatchVendor Advisory
FAQ
What is CVE-2021-20778?
CVE-2021-20778 is a vulnerability with a CVSS score of 7.5 (HIGH). Improper access control vulnerability in EC-CUBE 4.0.6 (EC-CUBE 4 series) allows a remote attacker to bypass access restriction and obtain sensitive information via unspecified vectors.
How severe is CVE-2021-20778?
CVE-2021-20778 has been rated HIGH with a CVSS base score of 7.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2021-20778?
Check the references section above for vendor advisories and patch information. Affected products include: Ec-Cube Ec-Cube.