CVE-2023-46845
07.11.2023, 08:15
EC-CUBE 3 series (3.0.0 to 3.0.18-p6) and 4 series (4.0.0 to 4.0.6-p3, 4.1.0 to 4.1.2-p2, and 4.2.0 to 4.2.2) contain an arbitrary code execution vulnerability due to improper settings of the template engine Twig included in the product. As a result, arbitrary code may be executed on the server where the product is running by a user with an administrative privilege.
Vendor | Product | Version |
---|---|---|
ec-cube | ec-cube | 3.0.0 ≤ 𝑥 ≤ 3.0.18 |
ec-cube | ec-cube | 4.0.0 ≤ 𝑥 ≤ 4.0.6 |
ec-cube | ec-cube | 4.1.0 ≤ 𝑥 ≤ 4.1.2 |
ec-cube | ec-cube | 4.2.0 ≤ 𝑥 < 4.2.3 |
ec-cube | ec-cube | 3.0.18:p1 |
ec-cube | ec-cube | 3.0.18:p2 |
ec-cube | ec-cube | 3.0.18:p3 |
ec-cube | ec-cube | 3.0.18:p4 |
ec-cube | ec-cube | 3.0.18:p5 |
ec-cube | ec-cube | 3.0.18:p6 |
ec-cube | ec-cube | 4.0.6:p1 |
ec-cube | ec-cube | 4.0.6:p2 |
ec-cube | ec-cube | 4.0.6:p3 |
ec-cube | ec-cube | 4.1.2:p1 |
ec-cube | ec-cube | 4.1.2:p2 |
𝑥
= Vulnerable software versions
References