Vulnerability Description
Authentication bypass vulnerability in NEXT ENGINE Integration Plugin (for EC-CUBE 2.0 series) all versions allows a remote unauthenticated attacker to alter the information stored in the system.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Next-Engine | Next Engine Integration | All versions |
Related Weaknesses (CWE)
References
- https://jvn.jp/en/jp/JVN50862842/Third Party Advisory
- https://main.next-engine.com/Usernotice/detail?id=1054Permissions Required
- https://jvn.jp/en/jp/JVN50862842/Third Party Advisory
- https://main.next-engine.com/Usernotice/detail?id=1054Permissions Required
FAQ
What is CVE-2023-27919?
CVE-2023-27919 is a vulnerability with a CVSS score of 5.3 (MEDIUM). Authentication bypass vulnerability in NEXT ENGINE Integration Plugin (for EC-CUBE 2.0 series) all versions allows a remote unauthenticated attacker to alter the information stored in the system.
How severe is CVE-2023-27919?
CVE-2023-27919 has been rated MEDIUM with a CVSS base score of 5.3/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2023-27919?
Check the references section above for vendor advisories and patch information. Affected products include: Next-Engine Next Engine Integration.