CVE-2023-22438

Cross-site scripting vulnerability in Contents Management of EC-CUBE 4 series (EC-CUBE 4.0.0 to 4.0.6-p2, EC-CUBE 4.1.0 to 4.1.2-p1, and EC-CUBE 4.2.0), EC-CUBE 3 series (EC-CUBE 3.0.0 to 3.0.18-p5), and EC-CUBE 2 series (EC-CUBE 2.11.0 to 2.11.5, EC-CUBE 2.12.0 to 2.12.6, EC-CUBE 2.13.0 to 2.13.5, and EC-CUBE 2.17.0 to 2.17.2) allows a remote authenticated attacker to inject an arbitrary script.
Cross-site Scripting
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
5.4 MEDIUM
NETWORK
LOW
LOW
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
jpcertCNA
---
---
CVEADP
---
---
CISA-ADPADP
5.4 MEDIUM
NETWORK
LOW
LOW
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
Base Score
CVSS 3.x
EPSS Score
Percentile: 49%
VendorProductVersion
ec-cubeec-cube
2.11.0 ≤
𝑥
≤ 2.11.5
ec-cubeec-cube
2.12.0 ≤
𝑥
≤ 2.12.6
ec-cubeec-cube
2.13.0 ≤
𝑥
≤ 2.13.5
ec-cubeec-cube
2.17.0 ≤
𝑥
≤ 2.17.2
ec-cubeec-cube
3.0.0 ≤
𝑥
≤ 3.0.18
ec-cubeec-cube
4.0.0 ≤
𝑥
≤ 4.0.6
ec-cubeec-cube
4.1.0 ≤
𝑥
≤ 4.1.2
ec-cubeec-cube
3.0.18:p1
ec-cubeec-cube
3.0.18:p2
ec-cubeec-cube
3.0.18:p3
ec-cubeec-cube
3.0.18:p4
ec-cubeec-cube
3.0.18:p5
ec-cubeec-cube
4.0.6:p1
ec-cubeec-cube
4.0.6:p2
ec-cubeec-cube
4.1.2:p1
ec-cubeec-cube
4.2.0
𝑥
= Vulnerable software versions