Executive brief
A security vulnerability exists in T-Soft E-Commerce, a platform used by businesses to manage online stores and sales. An attacker could trick an authenticated user, such as an administrator, into performing unintended actions on the platform without their knowledge. This could lead to unauthorized changes to store settings or the exposure of sensitive customer and business information.
Technical details
A Cross-Site Request Forgery (CSRF) vulnerability exists in Tekrom Technology Inc. T-Soft E-Commerce through version 28112025. The application fails to properly validate requests, allowing an attacker to craft malicious web pages or links that, when visited by an authenticated user, execute state-changing actions in the context of that user's session. This is a network-based attack that requires user interaction (UI:R). Successful exploitation could allow an attacker to modify data or settings within the e-commerce platform, potentially leading to unauthorized configuration changes or data disclosure.
Affected products
- Tekrom Technology Inc. T-Soft E-Commerce through 28112025
Timeline
- 2025-12-01: advisory: Initial disclosure by TR-CERT (USOM)