EC-CUBE 2.11.0 to 2.17.2-p1 contain a cross-site scripting vulnerability in "mail/template" and "products/product" of Management page. If this vulnerability is exploited, an arbitrary script may be executed on the web browser of the other administrator or the user who accessed the website using the product.
History

Tue, 08 Oct 2024 18:15:00 +0000

Type Values Removed Values Added
First Time appeared Ec-cube ec-cube 2
CPEs cpe:2.3:a:ec-cube:ec-cube_2:*:*:*:*:*:*:*:*
Vendors & Products Ec-cube ec-cube 2
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


cve-icon MITRE

Status: PUBLISHED

Assigner: jpcert

Published: 2023-08-17T06:37:01.773Z

Updated: 2024-10-08T17:38:02.195Z

Reserved: 2023-08-14T00:40:59.318Z

Link: CVE-2023-40281

cve-icon Vulnrichment

Updated: 2024-08-02T18:31:53.206Z

cve-icon NVD

Status : Modified

Published: 2023-08-17T07:15:44.153

Modified: 2024-11-21T08:19:07.793

Link: CVE-2023-40281

cve-icon Redhat

No data.