
Cloud Vulnerability DB
A community-led vulnerabilities database
Directory traversal vulnerability (CVE-2020-5590) affects EC-CUBE versions 3.0.0 to 3.0.18 and 4.0.0 to 4.0.3. The vulnerability was discovered and disclosed on January 6, 2020, impacting the e-commerce platform's file management system (JVN Report).
The vulnerability exists in the product registration functionality of the EC-CUBE management interface. It allows authenticated users with administrative access to perform directory traversal attacks through unspecified vectors. The vulnerability has been assigned a CVSS v3.0 Base Score of 4.3 (Medium) with vector string CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N (JVN Report).
When exploited, this vulnerability enables authenticated attackers to delete arbitrary files and directories on the server through the management screen. The attack requires valid administrative credentials and appropriate file system permissions (JVN Report).
The vulnerability requires authentication to the management interface and server file system permissions to be exploited. There are no public reports of this vulnerability being exploited in the wild (JVN Report).
For EC-CUBE 4.x users, updating to version 4.0.4 or later resolves the vulnerability. For EC-CUBE 3.x users, while no version update is available, security patches have been released. Users should apply the appropriate patch according to their version (EC-CUBE Advisory).
The vulnerability was initially reported by Silk Road Inc. to EC-CUBE, demonstrating responsible disclosure practices in the security community (EC-CUBE Advisory).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."