Filtered by vendor Ec-cube Subscriptions
Filtered by product Ec-cube 2 Subscriptions
Total 1 CVE
CVE Vendors Products Updated CVSS v3.1
CVE-2023-40281 1 Ec-cube 2 Ec-cube, Ec-cube 2 2024-11-21 4.8 Medium
EC-CUBE 2.11.0 to 2.17.2-p1 contain a cross-site scripting vulnerability in "mail/template" and "products/product" of Management page. If this vulnerability is exploited, an arbitrary script may be executed on the web browser of the other administrator or the user who accessed the website using the product.