{ "id": "CVE-2023-40281", "sourceIdentifier": "vultures@jpcert.or.jp", "published": "2023-08-17T07:15:44.153", "lastModified": "2023-08-17T12:53:44.537", "vulnStatus": "Awaiting Analysis", "descriptions": [ { "lang": "en", "value": "EC-CUBE 2.11.0 to 2.17.2-p1 contain a cross-site scripting vulnerability in \"mail/template\" and \"products/product\" of Management page.\r\nIf this vulnerability is exploited, an arbitrary script may be executed on the web browser of the other administrator or the user who accessed the website using the product." } ], "metrics": {}, "references": [ { "url": "https://jvn.jp/en/jp/JVN46993816/", "source": "vultures@jpcert.or.jp" }, { "url": "https://www.ec-cube.net/info/weakness/20230727/", "source": "vultures@jpcert.or.jp" } ] }