Description
Cross-site scripting vulnerability in EC-CUBE 4.0.0 to 4.0.5 allows a remote attacker to inject a specially crafted script in the specific input field of the EC web site which is created using EC-CUBE. As a result, it may lead to an arbitrary script execution on the administrator's web browser.
Analysis and contextual insights are available on OpenCVE Cloud.
Remediation
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2022-3535 | Cross-site scripting vulnerability in EC-CUBE 4.0.0 to 4.0.5 allows a remote attacker to inject a specially crafted script in the specific input field of the EC web site which is created using EC-CUBE. As a result, it may lead to an arbitrary script execution on the administrator's web browser. |
Github GHSA |
GHSA-c8mx-43cq-993w | EC-CUBE Cross-site scripting vulnerability |
References
History
No history.
Status: PUBLISHED
Assigner: jpcert
Published:
Updated: 2024-08-03T17:53:21.816Z
Reserved: 2020-12-17T00:00:00.000Z
Link: CVE-2021-20717
No data.
Status : Modified
Published: 2021-05-10T10:15:07.313
Modified: 2024-11-21T05:47:04.107
Link: CVE-2021-20717
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD
Github GHSA