CVE-2021-20841
CVE-2021-20841
Vexday Risk Score
3Low
SSVC decision (CISA)
Track
No exploitation signal → monitor
CVSS —EPSS 1.3%KEV nãoPoC —Nuclei —Metasploit —Patch —
Lifecycle
24 Nov 2021Published on NVD
Recommendation: Monitor — no exploitation signal at the moment.
Improper access control in Management screen of EC-CUBE 2 series 2.11.2 to 2.17.1 allows a remote authenticated attacker to bypass access restriction and to alter System settings via unspecified vectors.
Affected products
EC-CUBE CO.,LTD. · EC-CUBE 2 seriesWant to know if your infrastructure is exposed to this?
Talk to TrueHacking →