CVE-2021-20735
Summary
| CVE | CVE-2021-20735 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2021-06-22 02:15:00 UTC |
| Updated | 2021-07-01 18:22:00 UTC |
| Description | Cross-site scripting vulnerability in ETUNA EC-CUBE plugins (Delivery slip number plugin (3.0 series) 1.0.10 and earlier, Delivery slip number csv bulk registration plugin (3.0 series) 1.0.8 and earlier, and Delivery slip number mail plugin (3.0 series) 1.0.8 and earlier) allows remote attackers to inject an arbitrary script by executing a specific operation on the management page of EC-CUBE. |
Risk And Classification
Problem Types: CWE-79
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Ec-cube | Delivery Slip Number | All | All | All | All |
| Application | Ec-cube | Delivery Slip Number Csv Bulk Registration | All | All | All | All |
| Application | Ec-cube | Delivery Slip Number Mail | All | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| JVN#79254445: Multiple ETUNA EC-CUBE plugins vulnerable to cross-site scripting | MISC | jvn.jp | |
| 配送伝票番号メールプラグイン(3.0系)における脆弱性発覚と対応のお願い | EC-CUBE | MISC | www.ec-cube.net | |
| 配送伝票番号プラグイン(3.0系)における脆弱性発覚と対応のお願い | EC-CUBE | MISC | www.ec-cube.net | |
| 配送伝票番号csv一括登録プラグイン(3.0系)における脆弱性発覚と対応のお願い | EC-CUBE | MISC | www.ec-cube.net | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.