GHSA-jc55-crg7-pr35
GitHub Security Advisory
EC-CUBE Improper access control in Management screen
✓ GitHub Reviewed
MODERATE
Has CVE
Advisory Details
Improper access control in Management screen of EC-CUBE 2 series 2.11.2 to 2.17.1 allows a remote authenticated attacker to bypass access restriction and to alter System settings via unspecified vectors.
Affected Packages
Packagist
ec-cube/ec-cube
Affected versions:
2.11.2
(fixed in 2.17.2)
Related CVEs
Key Information
5.0
/10
Dataset
Last updated: July 12, 2025 6:29 AM
Data from GitHub Advisory Database. This information is provided for research and educational purposes.