EC-CUBE 2.11.0 to 2.17.2-p1 contain a cross-site scripting vulnerability in "mail/template" and "products/product" of Management page.
If this vulnerability is exploited, an arbitrary script may be executed on the web browser of the other administrator or the user who accessed the website using the product.
Advisories
Source ID Title
EUVD EUVD EUVD-2023-44874 EC-CUBE 2.11.0 to 2.17.2-p1 contain a cross-site scripting vulnerability in "mail/template" and "products/product" of Management page. If this vulnerability is exploited, an arbitrary script may be executed on the web browser of the other administrator or the user who accessed the website using the product.
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

Tue, 08 Oct 2024 18:15:00 +0000

Type Values Removed Values Added
First Time appeared Ec-cube ec-cube 2
CPEs cpe:2.3:a:ec-cube:ec-cube_2:*:*:*:*:*:*:*:*
Vendors & Products Ec-cube ec-cube 2
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


cve-icon MITRE

Status: PUBLISHED

Assigner: jpcert

Published:

Updated: 2024-10-08T17:38:02.195Z

Reserved: 2023-08-14T00:40:59.318Z

Link: CVE-2023-40281

cve-icon Vulnrichment

Updated: 2024-08-02T18:31:53.206Z

cve-icon NVD

Status : Modified

Published: 2023-08-17T07:15:44.153

Modified: 2024-11-21T08:19:07.793

Link: CVE-2023-40281

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.