CVE

Id
82942  
CVE No.
CVE-2015-5665  
Status
Candidate  
Description
Cross-site request forgery (CSRF) vulnerability in LOCKON EC-CUBE 2.11.0 through 2.13.3 allows remote attackers to hijack the authentication of arbitrary users for requests that write to PHP scripts, related to the doValidToken function.  
Phase
Assigned (20150724)  
Votes
None (candidate not yet proposed)  
Comments