5.4

CVE-2023-22438

Cross-site scripting vulnerability in Contents Management of EC-CUBE 4 series (EC-CUBE 4.0.0 to 4.0.6-p2, EC-CUBE 4.1.0 to 4.1.2-p1, and EC-CUBE 4.2.0), EC-CUBE 3 series (EC-CUBE 3.0.0 to 3.0.18-p5), and EC-CUBE 2 series (EC-CUBE 2.11.0 to 2.11.5, EC-CUBE 2.12.0 to 2.12.6, EC-CUBE 2.13.0 to 2.13.5, and EC-CUBE 2.17.0 to 2.17.2) allows a remote authenticated attacker to inject an arbitrary script.

Data is provided by the National Vulnerability Database (NVD)
Ec-cubeEc-cube Version >= 2.11.0 <= 2.11.5
Ec-cubeEc-cube Version >= 2.12.0 <= 2.12.6
Ec-cubeEc-cube Version >= 2.13.0 <= 2.13.5
Ec-cubeEc-cube Version >= 2.17.0 <= 2.17.2
Ec-cubeEc-cube Version >= 3.0.0 <= 3.0.18
Ec-cubeEc-cube Version >= 4.0.0 <= 4.0.6
Ec-cubeEc-cube Version >= 4.1.0 <= 4.1.2
Ec-cubeEc-cube Version3.0.18 Updatep1
Ec-cubeEc-cube Version3.0.18 Updatep2
Ec-cubeEc-cube Version3.0.18 Updatep3
Ec-cubeEc-cube Version3.0.18 Updatep4
Ec-cubeEc-cube Version3.0.18 Updatep5
Ec-cubeEc-cube Version4.0.6 Updatep1
Ec-cubeEc-cube Version4.0.6 Updatep2
Ec-cubeEc-cube Version4.1.2 Updatep1
Ec-cubeEc-cube Version4.2.0
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Type Source Score Percentile
EPSS FIRST.org 0.26% 0.464
CVSS Metriken
Source Base Score Exploit Score Impact Score Vector string
nvd@nist.gov 5.4 2.3 2.7
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
134c704f-9b21-4f2e-91b3-4a467353bcc0 5.4 2.3 2.7
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.