EC-CUBE 2.11.0 to 2.17.2-p1 contain a cross-site scripting vulnerability in "mail/template" and "products/product" of Management page.
If this vulnerability is exploited, an arbitrary script may be executed on the web browser of the other administrator or the user who accessed the website using the product.
References
Link | Resource |
---|---|
https://jvn.jp/en/jp/JVN46993816/ | Third Party Advisory |
https://www.ec-cube.net/info/weakness/20230727/ | Mitigation Patch Vendor Advisory |
Configurations
Configuration 1 (hide)
|
History
23 Aug 2023, 15:27
Type | Values Removed | Values Added |
---|---|---|
CWE | CWE-79 | |
References | (MISC) https://jvn.jp/en/jp/JVN46993816/ - Third Party Advisory | |
References | (MISC) https://www.ec-cube.net/info/weakness/20230727/ - Mitigation, Patch, Vendor Advisory | |
First Time |
Ec-cube ec-cube
Ec-cube |
|
CPE | cpe:2.3:a:ec-cube:ec-cube:2.13.5:-:*:*:*:*:*:* cpe:2.3:a:ec-cube:ec-cube:*:*:*:*:*:*:*:* cpe:2.3:a:ec-cube:ec-cube:2.13.5:patch1:*:*:*:*:*:* cpe:2.3:a:ec-cube:ec-cube:2.17.2:patch1:*:*:*:*:*:* cpe:2.3:a:ec-cube:ec-cube:2.17.2:-:*:*:*:*:*:* |
|
CVSS |
v2 : v3 : |
v2 : unknown
v3 : 4.8 |
17 Aug 2023, 07:15
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2023-08-17 07:15
Updated : 2024-02-28 20:33
NVD link : CVE-2023-40281
Mitre link : CVE-2023-40281
CVE.ORG link : CVE-2023-40281
JSON object : View
Products Affected
ec-cube
- ec-cube
CWE
CWE-79
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')