CVE Database
/

CVE-2022-38975

Back to search

CVE-2022-38975

Published: Sep 27, 2022

Modified: May 21, 2025

PUBLISHED

Description

DOM-based cross-site scripting vulnerability in EC-CUBE 4 series (EC-CUBE 4.0.0 to 4.1.2) allows a remote attacker to inject an arbitrary script by having an administrative user of the product to visit a specially crafted page.

VendorProductVersions

EC-CUBE CO.,LTD.

EC-CUBE 4 series

affected
EC-CUBE 4.0.0 to 4.1.2

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now