Published:2020/12/03  Last Updated:2020/12/03

JVN#24457594
Multiple vulnerabilities in EC-CUBE

Overview

EC-CUBE provided by EC-CUBE CO.,LTD. contains multiple vulnerabilities.

Products Affected

CVE-2020-5679

  • EC-CUBE versions from 3.0.0 to 3.0.18
CVE-2020-5680
  • EC-CUBE versions from 3.0.5 to 3.0.18

Description

EC-CUBE provided by EC-CUBE CO.,LTD. contains multiple vulnerabilities listed below.

  • Clickjacking attacks (CWE-1021) - CVE-2020-5679
    CVSS v3 CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N Base Score: 4.3
    CVSS v2 AV:N/AC:H/Au:N/C:N/I:P/A:N Base Score: 2.6
  • Improper input validation (CWE-20) - CVE-2020-5680
    CVSS v3 CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L Base Score: 5.3
    CVSS v2 AV:N/AC:L/Au:N/C:N/I:N/A:P Base Score: 5.0

Impact

  • If a user views a malicious page while logged in, unintended operations may be conducted - CVE-2020-5679
  • A remote attacker may be able to cause a denial-of-service (DoS) condition - CVE-2020-5680

Solution

Apply the patch
Apply the appropriate patch according to the information provided by the developer.

Vendor Status

Vendor Status Last Update Vendor Notes
EC-CUBE CO.,LTD. Vulnerable 2020/12/03 EC-CUBE CO.,LTD. website

References

JPCERT/CC Addendum

Vulnerability Analysis by JPCERT/CC

Credit

EC-CUBE CO.,LTD. reported these vulnerabilities to JPCERT/CC to notify users of its solution through JVN. JPCERT/CC and EC-CUBE CO.,LTD. coordinated under the Information Security Early Warning Partnership.

Other Information

JPCERT Alert
JPCERT Reports
CERT Advisory
CPNI Advisory
TRnotes
CVE CVE-2020-5679
CVE-2020-5680
JVN iPedia JVNDB-2020-000080

Update History

2020/12/03
Information under the section [Products Affected] was modified.