CyberRota Analysis
This is a medium severity vulnerability with a CVSS score of 5.1. It may be remotely exploitable.
CVE
CVE-2015-5665
Severity
MEDIUM
CVSS
5.1
EPSS
0.65%
Original NVD Description
Cross-site request forgery (CSRF) vulnerability in LOCKON EC-CUBE 2.11.0 through 2.13.3 allows remote attackers to hijack the authentication of arbitrary users for requests that write to PHP scripts, related to the doValidToken function.