CVE-2013-5993

medium
Published 2013-11-21 · Modified 2026-04-29
CVSS v3
CVSS v2
6.8
VIR risk
6.8

Description

Cross-site request forgery (CSRF) vulnerability in LOCKON EC-CUBE 2.11.0 through 2.13.0 allows remote attackers to hijack the authentication of arbitrary users via unspecified vectors related to refusals.

Predictions

Exploit likelihood
20%
Patch ETA

Heuristic predictions, AS-IS, for prioritization only.

Mitigations

vendor Authored 2026-05-27

Vendor advisory: vultures@jpcert.or.jp — http://www.ec-cube.net/info/weakness/weakness.php?id=53

vendor Authored 2026-05-27

Vendor advisory: vultures@jpcert.or.jp — http://svn.ec-cube.net/open_trac/changeset/23277

Application impact

VendorProductVersionsFixed
lockonec-cube2.11.0
lockonec-cube2.11.1
lockonec-cube2.11.2
lockonec-cube2.11.3
lockonec-cube2.11.4
lockonec-cube2.11.5
lockonec-cube2.12.0
lockonec-cube2.12.1
lockonec-cube2.12.2
lockonec-cube2.12.3
lockonec-cube2.12.3en
lockonec-cube2.12.3enp1
lockonec-cube2.12.3enp2
lockonec-cube2.12.4en
lockonec-cube2.12.5
lockonec-cube2.12.5en
lockonec-cube2.12.6
lockonec-cube2.12.6en
lockonec-cube2.13.0

References

CWEs

CWE-352

Verify integrity in audit chain (admin only). AS-IS.