2023-08-17 14:00:32 +00:00

24 lines
848 B
JSON

{
"id": "CVE-2023-40281",
"sourceIdentifier": "vultures@jpcert.or.jp",
"published": "2023-08-17T07:15:44.153",
"lastModified": "2023-08-17T12:53:44.537",
"vulnStatus": "Awaiting Analysis",
"descriptions": [
{
"lang": "en",
"value": "EC-CUBE 2.11.0 to 2.17.2-p1 contain a cross-site scripting vulnerability in \"mail/template\" and \"products/product\" of Management page.\r\nIf this vulnerability is exploited, an arbitrary script may be executed on the web browser of the other administrator or the user who accessed the website using the product."
}
],
"metrics": {},
"references": [
{
"url": "https://jvn.jp/en/jp/JVN46993816/",
"source": "vultures@jpcert.or.jp"
},
{
"url": "https://www.ec-cube.net/info/weakness/20230727/",
"source": "vultures@jpcert.or.jp"
}
]
}