CVE-2024-41924
- EPSS 0.11%
- Published 30.07.2024 09:15:05
- Last modified 18.03.2025 19:15:43
Acceptance of extraneous untrusted data with trusted data vulnerability exists in EC-CUBE 4 series. If this vulnerability is exploited, an attacker who obtained the administrative privilege may install an arbitrary PHP package. If the obsolete versio...
CVE-2023-46845
- EPSS 1.18%
- Published 07.11.2023 08:15:24
- Last modified 21.11.2024 08:29:24
EC-CUBE 3 series (3.0.0 to 3.0.18-p6) and 4 series (4.0.0 to 4.0.6-p3, 4.1.0 to 4.1.2-p2, and 4.2.0 to 4.2.2) contain an arbitrary code execution vulnerability due to improper settings of the template engine Twig included in the product. As a result,...
CVE-2023-40281
- EPSS 0.35%
- Published 17.08.2023 07:15:44
- Last modified 21.11.2024 08:19:07
EC-CUBE 2.11.0 to 2.17.2-p1 contain a cross-site scripting vulnerability in "mail/template" and "products/product" of Management page. If this vulnerability is exploited, an arbitrary script may be executed on the web browser of the other administra...
CVE-2023-25077
- EPSS 0.28%
- Published 06.03.2023 00:15:10
- Last modified 21.11.2024 07:49:03
Cross-site scripting vulnerability in Authentication Key Settings of EC-CUBE 4.0.0 to 4.0.6-p2, EC-CUBE 4.1.0 to 4.1.2-p1, and EC-CUBE 4.2.0 allows a remote authenticated attacker to inject an arbitrary script.
CVE-2023-22838
- EPSS 0.27%
- Published 06.03.2023 00:15:10
- Last modified 21.11.2024 07:45:29
Cross-site scripting vulnerability in Product List Screen and Product Detail Screen of EC-CUBE 4.0.0 to 4.0.6-p2, EC-CUBE 4.1.0 to 4.1.2-p1, and EC-CUBE 4.2.0 allows a remote authenticated attacker to inject an arbitrary script.
CVE-2023-22438
- EPSS 0.26%
- Published 06.03.2023 00:15:10
- Last modified 07.03.2025 22:15:37
Cross-site scripting vulnerability in Contents Management of EC-CUBE 4 series (EC-CUBE 4.0.0 to 4.0.6-p2, EC-CUBE 4.1.0 to 4.1.2-p1, and EC-CUBE 4.2.0), EC-CUBE 3 series (EC-CUBE 3.0.0 to 3.0.18-p5), and EC-CUBE 2 series (EC-CUBE 2.11.0 to 2.11.5, EC...
CVE-2022-40199
- EPSS 0.24%
- Published 27.09.2022 23:15:16
- Last modified 21.05.2025 19:16:00
Directory traversal vulnerability in EC-CUBE 3 series (EC-CUBE 3.0.0 to 3.0.18-p4 ) and EC-CUBE 4 series (EC-CUBE 4.0.0 to 4.1.2) allows a remote authenticated attacker with an administrative privilege to obtain the product's directory structure info...
CVE-2022-38975
- EPSS 0.22%
- Published 27.09.2022 23:15:15
- Last modified 21.05.2025 19:15:57
DOM-based cross-site scripting vulnerability in EC-CUBE 4 series (EC-CUBE 4.0.0 to 4.1.2) allows a remote attacker to inject an arbitrary script by having an administrative user of the product to visit a specially crafted page.
CVE-2022-25355
- EPSS 1.06%
- Published 24.02.2022 15:15:31
- Last modified 21.11.2024 06:52:03
EC-CUBE 3.0.0 to 3.0.18-p3 and EC-CUBE 4.0.0 to 4.1.1 improperly handle HTTP Host header values, which may lead a remote unauthenticated attacker to direct the vulnerable version of EC-CUBE to send an Email with some forged reissue-password URL to EC...
CVE-2021-20842
- EPSS 0.11%
- Published 24.11.2021 16:15:13
- Last modified 21.11.2024 05:47:15
Cross-site request forgery (CSRF) vulnerability in EC-CUBE 2 series 2.11.0 to 2.17.1 allows a remote attacker to hijack the authentication of Administrator and delete Administrator via a specially crafted web page.