CVE-2022-21179
Dashboard / Vulnerabilities / CVE-2022-21179
CVE-2022-21179
Summary:
Details: Cross-site request forgery (CSRF) vulnerability in EC-CUBE plugin 'Mail Magazine Management Plugin' ver4.0.0 to 4.1.1 (for EC-CUBE 4 series) and ver1.0.0 to 1.0.4 (for EC-CUBE 3 series) allows a remote unauthenticated attacker to hijack the authentication of an administrator via a specially crafted page, and Mail Magazine Templates and/or transmitted history information may be deleted unintendedly.
References: https://jvn.jp/en/jp/JVN67108459/index.html, https://www.ec-cube.net/info/weakness/20220221/mail_magazine_plugin.php, https://github.com/CVEProject/cvelistV5/tree/main/cves/2022/21xxx/CVE-2022-21179.json, https://nvd.nist.gov/vuln/detail/CVE-2022-21179
Affected packages
Package
Name:
Purl:
Affected ranges
Type: GIT
Events:
