CVE-2017-2139
MEDIUMCS-Cart Japanese Edition <4.3.10 - Auth Bypass
Title source: llmDescription
CS-Cart Japanese Edition v4.3.10 and earlier (excluding v2 and v3), CS-Cart Multivendor Japanese Edition v4.3.10 and earlier (excluding v2 and v3) allows remote attackers to bypass access restriction to obtain customer information via orders.pre.php.
Scores
CVSS v3
5.3
EPSS
0.0015
EPSS Percentile
35.7%
Attack Vector
NETWORK
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Classification
CWE
CWE-425
Status
published
Affected Products (4)
frogman_office_inc/cs-cart
< 4.3.10
frogman_office_inc/cs-cart
< 4.3.10
Frogman Office Inc./CS-Cart Japanese Edition
< v4.3.10 and earlier (excluding v2 and v3)
Frogman Office Inc./CS-Cart Multivendor Japanese Edition
< v4.3.10 and earlier (excluding v2 and v3)
Timeline
Published
Apr 28, 2017
Tracked Since
Feb 18, 2026