Loading...
Loading...
The process function in data/class/pages/admin/customer/LC_Page_Admin_Customer_SearchCustomer.php in EC-CUBE Ver2 2.4.0 RC1 through 2.4.1, and Community Edition r18068 through r18428, allows remote attackers to obtain sensitive information (customer data) via unknown vectors related to sessions.
December 8, 2009
April 23, 2026
See which npm, PyPI, Go, and Maven packages are affected by CVE-2009-4236
EchelonGraph automatically scans your cloud infrastructure and maps CVE exposure using blast radius analysis.