CVE-2023-22838

Cross-site scripting vulnerability in Product List Screen and Product Detail Screen of EC-CUBE 4.0.0 to 4.0.6-p2, EC-CUBE 4.1.0 to 4.1.2-p1, and EC-CUBE 4.2.0 allows a remote authenticated attacker to inject an arbitrary script.
Cross-site Scripting
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
5.4 MEDIUM
NETWORK
LOW
LOW
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
jpcertCNA
---
---
CVEADP
---
---
CISA-ADPADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 50%
VendorProductVersion
ec-cubeec-cube
4.0.0 ≤
𝑥
≤ 4.0.6
ec-cubeec-cube
4.1.0 ≤
𝑥
≤ 4.1.2
ec-cubeec-cube
4.0.6:p1
ec-cubeec-cube
4.0.6:p2
ec-cubeec-cube
4.1.2:p1
ec-cubeec-cube
4.2.0
𝑥
= Vulnerable software versions