Description
EC-CUBE 2.11.0 to 2.17.2-p1 contain a cross-site scripting vulnerability in "mail/template" and "products/product" of Management page.
If this vulnerability is exploited, an arbitrary script may be executed on the web browser of the other administrator or the user who accessed the website using the product.
Published: 2023-08-17
Score: 4.8 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

No analysis available yet.

Remediation

No remediation available yet.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2023-44874 EC-CUBE 2.11.0 to 2.17.2-p1 contain a cross-site scripting vulnerability in "mail/template" and "products/product" of Management page. If this vulnerability is exploited, an arbitrary script may be executed on the web browser of the other administrator or the user who accessed the website using the product.
History

Tue, 08 Oct 2024 18:15:00 +0000

Type Values Removed Values Added
First Time appeared Ec-cube ec-cube 2
CPEs cpe:2.3:a:ec-cube:ec-cube_2:*:*:*:*:*:*:*:*
Vendors & Products Ec-cube ec-cube 2
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Subscriptions

Ec-cube Ec-cube Ec-cube 2
cve-icon MITRE

Status: PUBLISHED

Assigner: jpcert

Published:

Updated: 2024-10-08T17:38:02.195Z

Reserved: 2023-08-14T00:40:59.318Z

Link: CVE-2023-40281

cve-icon Vulnrichment

Updated: 2024-08-02T18:31:53.206Z

cve-icon NVD

Status : Modified

Published: 2023-08-17T07:15:44.153

Modified: 2024-11-21T08:19:07.793

Link: CVE-2023-40281

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses