|
Description: | | Cross-site scripting vulnerability in EC-CUBE 4.0.0 to 4.0.5 allows a remote attacker to inject a specially crafted script in the specific input field of the EC web site which is created using EC-CUBE. As a result, it may lead to an arbitrary script execution on the administrator's web browser. |
|
Impact: | | An attacker can conduct a cross-site scripting attack to inject malicious client-side scripts into web pages viewed by other users, or to bypass access controls such as the same-origin policy, if affected version is installed. |
|
Affected OS: | | Windows, Linux, Others |
|
Reference: | | https://jvn.jp/en/jp/JVN97554111/index.html https://www.ec-cube.net/news/detail.php?news_id=383 https://www.ec-cube.net/news/detail.php?news_id=384
|
|