CVE-2023-27919: Next-Engine Next Engine Integration
Medium severity, CVSS 5.3. EPSS: 0.7% chance of exploitation in the next 30 days.
Authentication bypass vulnerability in NEXT ENGINE Integration Plugin (for EC-CUBE 2.0 series) all versions allows a remote unauthenticated attacker to alter the information stored in the system.
Affected products
- Next-Engine Next Engine Integration: any version
Published 2023-05-10. Last modified 2026-06-17.