Description
EC-CUBE 3 series (3.0.0 to 3.0.18-p6) and 4 series (4.0.0 to 4.0.6-p3, 4.1.0 to 4.1.2-p2, and 4.2.0 to 4.2.2) contain an arbitrary code execution vulnerability due to improper settings of the template engine Twig included in the product. As a result, arbitrary code may be executed on the server where the product is running by a user with an administrative privilege.
Analysis and contextual insights are available on OpenCVE Cloud.
Remediation
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2023-51011 | EC-CUBE 3 series (3.0.0 to 3.0.18-p6) and 4 series (4.0.0 to 4.0.6-p3, 4.1.0 to 4.1.2-p2, and 4.2.0 to 4.2.2) contain an arbitrary code execution vulnerability due to improper settings of the template engine Twig included in the product. As a result, arbitrary code may be executed on the server where the product is running by a user with an administrative privilege. |
References
History
No history.
Status: PUBLISHED
Assigner: jpcert
Published:
Updated: 2024-09-04T20:28:15.713Z
Reserved: 2023-10-27T08:05:25.926Z
Link: CVE-2023-46845
Updated: 2024-08-02T20:53:21.888Z
Status : Modified
Published: 2023-11-07T08:15:24.257
Modified: 2024-11-21T08:29:24.673
Link: CVE-2023-46845
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD