CVE Database
/

CVE-2022-25355

Back to search

CVE-2022-25355

Published: Feb 24, 2022

Modified: Aug 3, 2024

PUBLISHED

Description

EC-CUBE 3.0.0 to 3.0.18-p3 and EC-CUBE 4.0.0 to 4.1.1 improperly handle HTTP Host header values, which may lead a remote unauthenticated attacker to direct the vulnerable version of EC-CUBE to send an Email with some forged reissue-password URL to EC-CUBE users.

VendorProductVersions

EC-CUBE CO.,LTD.

EC-CUBE 3 series and EC-CUBE 4 series

affected
EC-CUBE 3.0.0 to 3.0.18-p3 and EC-CUBE 4.0.0 to 4.1.1

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now