CVE Database
/

CVE-2023-40281

Back to search

CVE-2023-40281

Published: Aug 17, 2023

Modified: Oct 8, 2024

PUBLISHED

Description

EC-CUBE 2.11.0 to 2.17.2-p1 contain a cross-site scripting vulnerability in "mail/template" and "products/product" of Management page. If this vulnerability is exploited, an arbitrary script may be executed on the web browser of the other administrator or the user who accessed the website using the product.

VendorProductVersions

EC-CUBE CO.,LTD.

EC-CUBE 2 series

affected
2.11.0 to 2.17.2-p1

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now