CVE-2021-20717
Summary
| CVE | CVE-2021-20717 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2021-05-10 10:15:00 UTC |
| Updated | 2021-05-17 16:22:00 UTC |
| Description | Cross-site scripting vulnerability in EC-CUBE 4.0.0 to 4.0.5 allows a remote attacker to inject a specially crafted script in the specific input field of the EC web site which is created using EC-CUBE. As a result, it may lead to an arbitrary script execution on the administrator's web browser. |
Risk And Classification
Problem Types: CWE-79
NVD Known Affected Configurations (CPE 2.3)
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| JVN#97554111: EC-CUBE vulnerable to cross-site scripting | MISC | jvn.jp | |
| 【重要】EC-CUBE 4.0系における緊急度「高」の脆弱性発覚と対応のお願い(2021/5/9 14:20更新)|ECサイト構築・リニューアルは「ECオープンプラットフォームEC-CUBE」 | MISC | www.ec-cube.net | |
| 脆弱性対応版「EC-CUBE 4.0.5-p1」をリリース|ECサイト構築・リニューアルは「ECオープンプラットフォームEC-CUBE」 | MISC | www.ec-cube.net | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.