CVE-2017-2139

MEDIUM

CS-Cart Japanese Edition <4.3.10 - Auth Bypass

Title source: llm

Description

CS-Cart Japanese Edition v4.3.10 and earlier (excluding v2 and v3), CS-Cart Multivendor Japanese Edition v4.3.10 and earlier (excluding v2 and v3) allows remote attackers to bypass access restriction to obtain customer information via orders.pre.php.

Scores

CVSS v3 5.3
EPSS 0.0015
EPSS Percentile 35.7%
Attack Vector NETWORK
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N

Classification

CWE
CWE-425
Status published

Affected Products (4)

frogman_office_inc/cs-cart < 4.3.10
frogman_office_inc/cs-cart < 4.3.10
Frogman Office Inc./CS-Cart Japanese Edition < v4.3.10 and earlier (excluding v2 and v3)
Frogman Office Inc./CS-Cart Multivendor Japanese Edition < v4.3.10 and earlier (excluding v2 and v3)

Timeline

Published Apr 28, 2017
Tracked Since Feb 18, 2026