Vulnerabilities > Frogman Office INC

DATE CVE VULNERABILITY TITLE RISK
2017-04-28 CVE-2017-2143 Forced Browsing vulnerability in Frogman Office INC products
CS-Cart Japanese Edition v4.3.10-jp-1 and earlier, CS-Cart Multivendor Japanese Edition v4.3.10-jp-1 and earlier allows remote attackers to bypass access restriction to create a request to return a customer purchased item via rma.post.php.
network
low complexity
frogman-office-inc CWE-425
5.0
2017-04-28 CVE-2017-2139 Forced Browsing vulnerability in Frogman Office INC Cs-Cart
CS-Cart Japanese Edition v4.3.10 and earlier (excluding v2 and v3), CS-Cart Multivendor Japanese Edition v4.3.10 and earlier (excluding v2 and v3) allows remote attackers to bypass access restriction to obtain customer information via orders.pre.php.
network
low complexity
frogman-office-inc CWE-425
5.0