EC-CUBE 2.11.0 to 2.17.2-p1 contain a cross-site scripting vulnerability in "mail/template" and "products/product" of Management page.
If this vulnerability is exploited, an arbitrary script may be executed on the web browser of the other administrator or the user who accessed the website using the product.
References
Link | Resource |
---|---|
https://www.ec-cube.net/info/weakness/20230727/ | Mitigation Patch Vendor Advisory |
https://jvn.jp/en/jp/JVN46993816/ | Third Party Advisory |
Configurations
Configuration 1 (hide)
|
History
23 Aug 2023, 15:27
Type | Values Removed | Values Added |
---|---|---|
First Time |
Ec-cube
Ec-cube ec-cube |
|
CVSS |
v2 : v3 : |
v2 : unknown
v3 : 4.8 |
CPE | cpe:2.3:a:ec-cube:ec-cube:2.13.5:patch1:*:*:*:*:*:* cpe:2.3:a:ec-cube:ec-cube:2.17.2:-:*:*:*:*:*:* cpe:2.3:a:ec-cube:ec-cube:*:*:*:*:*:*:*:* cpe:2.3:a:ec-cube:ec-cube:2.17.2:patch1:*:*:*:*:*:* cpe:2.3:a:ec-cube:ec-cube:2.13.5:-:*:*:*:*:*:* |
|
References | (MISC) https://jvn.jp/en/jp/JVN46993816/ - Third Party Advisory | |
References | (MISC) https://www.ec-cube.net/info/weakness/20230727/ - Mitigation, Patch, Vendor Advisory | |
CWE | CWE-79 |
17 Aug 2023, 07:15
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2023-08-17 07:15
Updated : 2023-08-23 15:27
NVD link : CVE-2023-40281
Mitre link : CVE-2023-40281
JSON object : View
Products Affected
ec-cube
- ec-cube
CWE
CWE-79
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')