Cross-site request forgery (CSRF) vulnerability in LOCKON EC-CUBE 2.11.0 through 2.13.0 allows remote attackers to hijack the authentication of arbitrary users via unspecified vectors related to refusals.Referenceshttp://jvn.jp/en/jp/JVN11221613/index.htmlhttp://jvndb.jvn.jp/jvndb/JVNDB-2013-000097http://www.ec-cube.net/info/weakness/weakness.php?id=53http://svn.ec-cube.net/open_trac/changeset/23277