Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
The process function in data/class/pages/admin/customer/LC_Page_Admin_Customer_SearchCustomer.php in EC-CUBE Ver2 2.4.0 RC1 through 2.4.1, and Community Edition r18068 through r18428, allows remote attackers to obtain sensitive information (customer data) via unknown vectors related to sessions.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
EC-CUBE 'LC_Page_Admin_Customer_SearchCustomer.php' 信息泄露漏洞
Vulnerability Description
EC-CUBE为网店系统构筑软件。EC-CUBE Ver2 2.4.0 RC1到2.4.1,以及Community Edition r18068到r18428中的data/class/pages/admin/customer/LC_Page_Admin_Customer_SearchCustomer.php的程序函数允许远程攻击者借助于会谈相关的未明向量获得敏感信息(客户数据)。
CVSS Information
N/A
Vulnerability Type
N/A