{"api_version":"1","generated_at":"2026-07-05T23:31:30+00:00","cve":"CVE-2017-10886","urls":{"html":"https://cve.report/CVE-2017-10886","api":"https://cve.report/api/cve/CVE-2017-10886.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2017-10886","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2017-10886"},"summary":{"title":"CVE-2017-10886","description":"Cross-site scripting vulnerability in CS-Cart Japanese Edition v4.3.10 and earlier (excluding v2 and v3), CS-Cart Multivendor Japanese Edition v4.3.10 and earlier (excluding v2 and v3) allows an attacker to inject arbitrary web script or HTML via unspecified vectors.","state":"PUBLISHED","assigner":"jpcert","published_at":"2017-11-17 14:29:00","updated_at":"2025-04-20 01:37:25"},"problem_types":["CWE-79","Cross-site scripting"],"metrics":[{"version":"3.0","source":"nvd@nist.gov","type":"Primary","score":"5.4","severity":"MEDIUM","vector":"CVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N","data":{"version":"3.0","vectorString":"CVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N","baseScore":5.4,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"REQUIRED","scope":"CHANGED","confidentialityImpact":"LOW","integrityImpact":"LOW","availabilityImpact":"NONE"}},{"version":"2.0","source":"nvd@nist.gov","type":"Primary","score":"3.5","severity":"","vector":"AV:N/AC:M/Au:S/C:N/I:P/A:N","data":{"version":"2.0","vectorString":"AV:N/AC:M/Au:S/C:N/I:P/A:N","baseScore":3.5,"accessVector":"NETWORK","accessComplexity":"MEDIUM","authentication":"SINGLE","confidentialityImpact":"NONE","integrityImpact":"PARTIAL","availabilityImpact":"NONE"}}],"references":[{"url":"http://tips.cs-cart.jp/fix-jvn-29602086.html","name":"http://tips.cs-cart.jp/fix-jvn-29602086.html","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"],"title":"セキュリティ :: 【JVN#29602086】 2017年11月13日に公表されたXSS脆弱性への対応方法 - ブログ記事","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://jvn.jp/en/jp/JVN29602086/index.html","name":"https://jvn.jp/en/jp/JVN29602086/index.html","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Third Party Advisory","VDB Entry"],"title":"JVN#29602086: CS-Cart Japanese Edition vulnerable to cross-site scripting","mime":"text/xml","httpstatus":"200","archivestatus":"200"},{"url":"https://www.cve.org/CVERecord?id=CVE-2017-10886","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2017-10886","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"Frogman Office Inc.","product":"CS-Cart Japanese Edition","version":"affected v4.3.10 and earlier (excluding v2 and v3)","platforms":[]},{"source":"CNA","vendor":"Frogman Office Inc.","product":"CS-Cart Multivendor Japanese Edition","version":"affected v4.3.10 and earlier (excluding v2 and v3)","platforms":[]}],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2017","cve_id":"10886","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"cs-cart","cpe5":"cs-cart","cpe6":"4.0.1","cpe7":"*","cpe8":"*","cpe9":"ja","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2017","cve_id":"10886","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"cs-cart","cpe5":"cs-cart","cpe6":"4.0.2","cpe7":"*","cpe8":"*","cpe9":"ja","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2017","cve_id":"10886","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"cs-cart","cpe5":"cs-cart","cpe6":"4.0.3","cpe7":"*","cpe8":"*","cpe9":"ja","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2017","cve_id":"10886","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"cs-cart","cpe5":"cs-cart","cpe6":"4.1.1","cpe7":"*","cpe8":"*","cpe9":"ja","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2017","cve_id":"10886","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"cs-cart","cpe5":"cs-cart","cpe6":"4.1.2","cpe7":"*","cpe8":"*","cpe9":"ja","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2017","cve_id":"10886","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"cs-cart","cpe5":"cs-cart","cpe6":"4.1.3","cpe7":"*","cpe8":"*","cpe9":"ja","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2017","cve_id":"10886","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"cs-cart","cpe5":"cs-cart","cpe6":"4.1.4","cpe7":"*","cpe8":"*","cpe9":"ja","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2017","cve_id":"10886","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"cs-cart","cpe5":"cs-cart","cpe6":"4.2.1","cpe7":"*","cpe8":"*","cpe9":"ja","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2017","cve_id":"10886","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"cs-cart","cpe5":"cs-cart","cpe6":"4.2.2","cpe7":"*","cpe8":"*","cpe9":"ja","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2017","cve_id":"10886","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"cs-cart","cpe5":"cs-cart","cpe6":"4.2.3","cpe7":"*","cpe8":"*","cpe9":"ja","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2017","cve_id":"10886","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"cs-cart","cpe5":"cs-cart","cpe6":"4.2.4","cpe7":"*","cpe8":"*","cpe9":"ja","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2017","cve_id":"10886","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"cs-cart","cpe5":"cs-cart","cpe6":"4.3.1","cpe7":"*","cpe8":"*","cpe9":"ja","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2017","cve_id":"10886","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"cs-cart","cpe5":"cs-cart","cpe6":"4.3.10","cpe7":"*","cpe8":"*","cpe9":"ja","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2017","cve_id":"10886","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"cs-cart","cpe5":"cs-cart","cpe6":"4.3.2","cpe7":"*","cpe8":"*","cpe9":"ja","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2017","cve_id":"10886","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"cs-cart","cpe5":"cs-cart","cpe6":"4.3.3","cpe7":"*","cpe8":"*","cpe9":"ja","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2017","cve_id":"10886","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"cs-cart","cpe5":"cs-cart","cpe6":"4.3.4","cpe7":"*","cpe8":"*","cpe9":"ja","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2017","cve_id":"10886","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"cs-cart","cpe5":"cs-cart","cpe6":"4.3.5","cpe7":"*","cpe8":"*","cpe9":"ja","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2017","cve_id":"10886","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"cs-cart","cpe5":"cs-cart","cpe6":"4.3.6","cpe7":"*","cpe8":"*","cpe9":"ja","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2017","cve_id":"10886","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"cs-cart","cpe5":"cs-cart","cpe6":"4.3.7","cpe7":"*","cpe8":"*","cpe9":"ja","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2017","cve_id":"10886","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"cs-cart","cpe5":"cs-cart","cpe6":"4.3.8","cpe7":"*","cpe8":"*","cpe9":"ja","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2017","cve_id":"10886","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"cs-cart","cpe5":"cs-cart","cpe6":"4.3.9","cpe7":"*","cpe8":"*","cpe9":"ja","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2017","cve_id":"10886","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"cs-cart","cpe5":"cs-cart_multivendor","cpe6":"4.0.1","cpe7":"*","cpe8":"*","cpe9":"ja","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2017","cve_id":"10886","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"cs-cart","cpe5":"cs-cart_multivendor","cpe6":"4.0.2","cpe7":"*","cpe8":"*","cpe9":"ja","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2017","cve_id":"10886","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"cs-cart","cpe5":"cs-cart_multivendor","cpe6":"4.0.3","cpe7":"*","cpe8":"*","cpe9":"ja","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2017","cve_id":"10886","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"cs-cart","cpe5":"cs-cart_multivendor","cpe6":"4.1.1","cpe7":"*","cpe8":"*","cpe9":"ja","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2017","cve_id":"10886","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"cs-cart","cpe5":"cs-cart_multivendor","cpe6":"4.1.2","cpe7":"*","cpe8":"*","cpe9":"ja","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2017","cve_id":"10886","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"cs-cart","cpe5":"cs-cart_multivendor","cpe6":"4.1.3","cpe7":"*","cpe8":"*","cpe9":"ja","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2017","cve_id":"10886","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"cs-cart","cpe5":"cs-cart_multivendor","cpe6":"4.1.4","cpe7":"*","cpe8":"*","cpe9":"ja","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2017","cve_id":"10886","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"cs-cart","cpe5":"cs-cart_multivendor","cpe6":"4.2.1","cpe7":"*","cpe8":"*","cpe9":"ja","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2017","cve_id":"10886","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"cs-cart","cpe5":"cs-cart_multivendor","cpe6":"4.2.2","cpe7":"*","cpe8":"*","cpe9":"ja","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2017","cve_id":"10886","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"cs-cart","cpe5":"cs-cart_multivendor","cpe6":"4.2.3","cpe7":"*","cpe8":"*","cpe9":"ja","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2017","cve_id":"10886","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"cs-cart","cpe5":"cs-cart_multivendor","cpe6":"4.2.4","cpe7":"*","cpe8":"*","cpe9":"ja","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2017","cve_id":"10886","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"cs-cart","cpe5":"cs-cart_multivendor","cpe6":"4.3.1","cpe7":"*","cpe8":"*","cpe9":"ja","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2017","cve_id":"10886","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"cs-cart","cpe5":"cs-cart_multivendor","cpe6":"4.3.10","cpe7":"*","cpe8":"*","cpe9":"ja","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2017","cve_id":"10886","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"cs-cart","cpe5":"cs-cart_multivendor","cpe6":"4.3.2","cpe7":"*","cpe8":"*","cpe9":"ja","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2017","cve_id":"10886","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"cs-cart","cpe5":"cs-cart_multivendor","cpe6":"4.3.3","cpe7":"*","cpe8":"*","cpe9":"ja","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2017","cve_id":"10886","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"cs-cart","cpe5":"cs-cart_multivendor","cpe6":"4.3.4","cpe7":"*","cpe8":"*","cpe9":"ja","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2017","cve_id":"10886","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"cs-cart","cpe5":"cs-cart_multivendor","cpe6":"4.3.5","cpe7":"*","cpe8":"*","cpe9":"ja","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2017","cve_id":"10886","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"cs-cart","cpe5":"cs-cart_multivendor","cpe6":"4.3.6","cpe7":"*","cpe8":"*","cpe9":"ja","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2017","cve_id":"10886","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"cs-cart","cpe5":"cs-cart_multivendor","cpe6":"4.3.7","cpe7":"*","cpe8":"*","cpe9":"ja","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2017","cve_id":"10886","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"cs-cart","cpe5":"cs-cart_multivendor","cpe6":"4.3.8","cpe7":"*","cpe8":"*","cpe9":"ja","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2017","cve_id":"10886","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"cs-cart","cpe5":"cs-cart_multivendor","cpe6":"4.3.9","cpe7":"*","cpe8":"*","cpe9":"ja","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":{"cve_year":"2017","cve_id":"10886","cve":"CVE-2017-10886","epss":"0.002530000","percentile":"0.485810000","score_date":"2026-05-13","updated_at":"2026-05-14 00:03:18"},"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"adp":[{"providerMetadata":{"dateUpdated":"2024-08-05T17:50:12.728Z","orgId":"af854a3a-2127-422b-91ae-364da2661108","shortName":"CVE"},"references":[{"name":"JVN#29602086","tags":["third-party-advisory","x_refsource_JVN","x_transferred"],"url":"https://jvn.jp/en/jp/JVN29602086/index.html"},{"tags":["x_refsource_CONFIRM","x_transferred"],"url":"http://tips.cs-cart.jp/fix-jvn-29602086.html"}],"title":"CVE Program Container"}],"cna":{"affected":[{"product":"CS-Cart Japanese Edition","vendor":"Frogman Office Inc.","versions":[{"status":"affected","version":"v4.3.10 and earlier (excluding v2 and v3)"}]},{"product":"CS-Cart Multivendor Japanese Edition","vendor":"Frogman Office Inc.","versions":[{"status":"affected","version":"v4.3.10 and earlier (excluding v2 and v3)"}]}],"datePublic":"2017-11-13T00:00:00.000Z","descriptions":[{"lang":"en","value":"Cross-site scripting vulnerability in CS-Cart Japanese Edition v4.3.10 and earlier (excluding v2 and v3), CS-Cart Multivendor Japanese Edition v4.3.10 and earlier (excluding v2 and v3) allows an attacker to inject arbitrary web script or HTML via unspecified vectors."}],"problemTypes":[{"descriptions":[{"description":"Cross-site scripting","lang":"en","type":"text"}]}],"providerMetadata":{"dateUpdated":"2017-11-17T13:57:01.000Z","orgId":"ede6fdc4-6654-4307-a26d-3331c018e2ce","shortName":"jpcert"},"references":[{"name":"JVN#29602086","tags":["third-party-advisory","x_refsource_JVN"],"url":"https://jvn.jp/en/jp/JVN29602086/index.html"},{"tags":["x_refsource_CONFIRM"],"url":"http://tips.cs-cart.jp/fix-jvn-29602086.html"}],"x_legacyV4Record":{"CVE_data_meta":{"ASSIGNER":"vultures@jpcert.or.jp","ID":"CVE-2017-10886","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"CS-Cart Japanese Edition","version":{"version_data":[{"version_value":"v4.3.10 and earlier (excluding v2 and v3)"}]}},{"product_name":"CS-Cart Multivendor Japanese Edition","version":{"version_data":[{"version_value":"v4.3.10 and earlier (excluding v2 and v3)"}]}}]},"vendor_name":"Frogman Office Inc."}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"Cross-site scripting vulnerability in CS-Cart Japanese Edition v4.3.10 and earlier (excluding v2 and v3), CS-Cart Multivendor Japanese Edition v4.3.10 and earlier (excluding v2 and v3) allows an attacker to inject arbitrary web script or HTML via unspecified vectors."}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"Cross-site scripting"}]}]},"references":{"reference_data":[{"name":"JVN#29602086","refsource":"JVN","url":"https://jvn.jp/en/jp/JVN29602086/index.html"},{"name":"http://tips.cs-cart.jp/fix-jvn-29602086.html","refsource":"CONFIRM","url":"http://tips.cs-cart.jp/fix-jvn-29602086.html"}]}}}},"cveMetadata":{"assignerOrgId":"ede6fdc4-6654-4307-a26d-3331c018e2ce","assignerShortName":"jpcert","cveId":"CVE-2017-10886","datePublished":"2017-11-17T14:00:00.000Z","dateReserved":"2017-07-04T00:00:00.000Z","dateUpdated":"2024-08-05T17:50:12.728Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.1"},"nvd":{"publishedDate":"2017-11-17 14:29:00","lastModifiedDate":"2025-04-20 01:37:25","problem_types":["CWE-79","Cross-site scripting"],"metrics":{"cvssMetricV30":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.0","vectorString":"CVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N","baseScore":5.4,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"REQUIRED","scope":"CHANGED","confidentialityImpact":"LOW","integrityImpact":"LOW","availabilityImpact":"NONE"},"exploitabilityScore":2.3,"impactScore":2.7}],"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:M/Au:S/C:N/I:P/A:N","baseScore":3.5,"accessVector":"NETWORK","accessComplexity":"MEDIUM","authentication":"SINGLE","confidentialityImpact":"NONE","integrityImpact":"PARTIAL","availabilityImpact":"NONE"},"baseSeverity":"LOW","exploitabilityScore":6.8,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":true}]},"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:cs-cart:cs-cart:4.0.1:*:*:ja:*:*:*:*","matchCriteriaId":"7CEDDB5F-0042-4F91-A374-72F6EA9FE8C5"},{"vulnerable":true,"criteria":"cpe:2.3:a:cs-cart:cs-cart:4.0.2:*:*:ja:*:*:*:*","matchCriteriaId":"09888B17-F813-4B09-971A-5EE64C84B223"},{"vulnerable":true,"criteria":"cpe:2.3:a:cs-cart:cs-cart:4.0.3:*:*:ja:*:*:*:*","matchCriteriaId":"A4586C46-0266-4D02-A218-11E9B6C75258"},{"vulnerable":true,"criteria":"cpe:2.3:a:cs-cart:cs-cart:4.1.1:*:*:ja:*:*:*:*","matchCriteriaId":"1795D3A8-F3B7-4B00-8221-62F597888DE4"},{"vulnerable":true,"criteria":"cpe:2.3:a:cs-cart:cs-cart:4.1.2:*:*:ja:*:*:*:*","matchCriteriaId":"060D0460-2ECD-41E5-934F-EDC39D75AF28"},{"vulnerable":true,"criteria":"cpe:2.3:a:cs-cart:cs-cart:4.1.3:*:*:ja:*:*:*:*","matchCriteriaId":"34F92804-A076-4877-A35A-3C6E9ABCC60D"},{"vulnerable":true,"criteria":"cpe:2.3:a:cs-cart:cs-cart:4.1.4:*:*:ja:*:*:*:*","matchCriteriaId":"5689776B-779D-4C83-B837-FC97F53A3F6B"},{"vulnerable":true,"criteria":"cpe:2.3:a:cs-cart:cs-cart:4.2.1:*:*:ja:*:*:*:*","matchCriteriaId":"36C1D456-0A84-4A7A-9CDF-CC25013EA2D0"},{"vulnerable":true,"criteria":"cpe:2.3:a:cs-cart:cs-cart:4.2.2:*:*:ja:*:*:*:*","matchCriteriaId":"215F550E-3946-4FC1-A53D-2159FB085C42"},{"vulnerable":true,"criteria":"cpe:2.3:a:cs-cart:cs-cart:4.2.3:*:*:ja:*:*:*:*","matchCriteriaId":"DEBEC0F2-04BC-4EDC-B406-8566EBA6BFC7"},{"vulnerable":true,"criteria":"cpe:2.3:a:cs-cart:cs-cart:4.2.4:*:*:ja:*:*:*:*","matchCriteriaId":"6696CFF2-8CA3-476C-93C4-26DD2DD03EF7"},{"vulnerable":true,"criteria":"cpe:2.3:a:cs-cart:cs-cart:4.3.1:*:*:ja:*:*:*:*","matchCriteriaId":"1AAFC419-F733-4513-8C91-09752D8D59F1"},{"vulnerable":true,"criteria":"cpe:2.3:a:cs-cart:cs-cart:4.3.2:*:*:ja:*:*:*:*","matchCriteriaId":"42F2E657-E293-4375-A9DA-10427E805A64"},{"vulnerable":true,"criteria":"cpe:2.3:a:cs-cart:cs-cart:4.3.3:*:*:ja:*:*:*:*","matchCriteriaId":"01132E65-36E4-46BF-92B8-8C650A809C59"},{"vulnerable":true,"criteria":"cpe:2.3:a:cs-cart:cs-cart:4.3.4:*:*:ja:*:*:*:*","matchCriteriaId":"7B7A9A8F-7429-44C3-92DA-A7FE24731F9F"},{"vulnerable":true,"criteria":"cpe:2.3:a:cs-cart:cs-cart:4.3.5:*:*:ja:*:*:*:*","matchCriteriaId":"AC17365C-07EB-468F-9645-C9F17BE39129"},{"vulnerable":true,"criteria":"cpe:2.3:a:cs-cart:cs-cart:4.3.6:*:*:ja:*:*:*:*","matchCriteriaId":"44A94CAE-30F6-414E-806B-721FE65AFFCA"},{"vulnerable":true,"criteria":"cpe:2.3:a:cs-cart:cs-cart:4.3.7:*:*:ja:*:*:*:*","matchCriteriaId":"BAA8F0F8-3EB4-4D5E-88E1-F92B8A36977F"},{"vulnerable":true,"criteria":"cpe:2.3:a:cs-cart:cs-cart:4.3.8:*:*:ja:*:*:*:*","matchCriteriaId":"00CAB998-2FF9-4352-90ED-A6102BFA0223"},{"vulnerable":true,"criteria":"cpe:2.3:a:cs-cart:cs-cart:4.3.9:*:*:ja:*:*:*:*","matchCriteriaId":"0E0F42A0-15F9-4587-A608-52D9F9EB18D0"},{"vulnerable":true,"criteria":"cpe:2.3:a:cs-cart:cs-cart:4.3.10:*:*:ja:*:*:*:*","matchCriteriaId":"BA6DD97F-4315-4483-9540-868E4EF479A5"},{"vulnerable":true,"criteria":"cpe:2.3:a:cs-cart:cs-cart_multivendor:4.0.1:*:*:ja:*:*:*:*","matchCriteriaId":"5ADC7033-B392-46DB-B04B-2B7AB514AFA2"},{"vulnerable":true,"criteria":"cpe:2.3:a:cs-cart:cs-cart_multivendor:4.0.2:*:*:ja:*:*:*:*","matchCriteriaId":"D2531207-2B53-4CEF-9724-A3D958DC38D9"},{"vulnerable":true,"criteria":"cpe:2.3:a:cs-cart:cs-cart_multivendor:4.0.3:*:*:ja:*:*:*:*","matchCriteriaId":"BDC2FD45-31E7-4838-85A9-3C184DDA68C8"},{"vulnerable":true,"criteria":"cpe:2.3:a:cs-cart:cs-cart_multivendor:4.1.1:*:*:ja:*:*:*:*","matchCriteriaId":"0B3B4C1C-B63E-451D-BC9A-CB45C3A5A4FC"},{"vulnerable":true,"criteria":"cpe:2.3:a:cs-cart:cs-cart_multivendor:4.1.2:*:*:ja:*:*:*:*","matchCriteriaId":"03A50D9D-4321-48C7-B362-D7D02768E30C"},{"vulnerable":true,"criteria":"cpe:2.3:a:cs-cart:cs-cart_multivendor:4.1.3:*:*:ja:*:*:*:*","matchCriteriaId":"178E2618-9FED-452F-B379-36D50D544BC4"},{"vulnerable":true,"criteria":"cpe:2.3:a:cs-cart:cs-cart_multivendor:4.1.4:*:*:ja:*:*:*:*","matchCriteriaId":"2C822C02-3E28-4412-803D-10F2D5AC4D5D"},{"vulnerable":true,"criteria":"cpe:2.3:a:cs-cart:cs-cart_multivendor:4.2.1:*:*:ja:*:*:*:*","matchCriteriaId":"5B43CD84-D885-4006-BADA-7E1A3012608C"},{"vulnerable":true,"criteria":"cpe:2.3:a:cs-cart:cs-cart_multivendor:4.2.2:*:*:ja:*:*:*:*","matchCriteriaId":"CD843B2F-A3D5-49A5-B9F0-B8FC146931AF"},{"vulnerable":true,"criteria":"cpe:2.3:a:cs-cart:cs-cart_multivendor:4.2.3:*:*:ja:*:*:*:*","matchCriteriaId":"01C42531-506B-41FF-ADD8-BFE4C492E5D0"},{"vulnerable":true,"criteria":"cpe:2.3:a:cs-cart:cs-cart_multivendor:4.2.4:*:*:ja:*:*:*:*","matchCriteriaId":"3BE29145-9836-4A10-AF2D-BB1EE63820C7"},{"vulnerable":true,"criteria":"cpe:2.3:a:cs-cart:cs-cart_multivendor:4.3.1:*:*:ja:*:*:*:*","matchCriteriaId":"8F33ECEC-3011-4131-AE8F-E44DF85F33ED"},{"vulnerable":true,"criteria":"cpe:2.3:a:cs-cart:cs-cart_multivendor:4.3.2:*:*:ja:*:*:*:*","matchCriteriaId":"4C2FEE8A-DB91-43E6-9DC1-AB78DE23FF81"},{"vulnerable":true,"criteria":"cpe:2.3:a:cs-cart:cs-cart_multivendor:4.3.3:*:*:ja:*:*:*:*","matchCriteriaId":"FD83A201-9C79-47BA-BA15-145A46FEEBEF"},{"vulnerable":true,"criteria":"cpe:2.3:a:cs-cart:cs-cart_multivendor:4.3.4:*:*:ja:*:*:*:*","matchCriteriaId":"4A03FAC1-4E22-4344-95E1-87A409C98507"},{"vulnerable":true,"criteria":"cpe:2.3:a:cs-cart:cs-cart_multivendor:4.3.5:*:*:ja:*:*:*:*","matchCriteriaId":"1CC2EBD9-05B5-402C-B650-33BB86FC6043"},{"vulnerable":true,"criteria":"cpe:2.3:a:cs-cart:cs-cart_multivendor:4.3.6:*:*:ja:*:*:*:*","matchCriteriaId":"1D9545E8-20E6-46E1-BBDB-662D07DB1E4B"},{"vulnerable":true,"criteria":"cpe:2.3:a:cs-cart:cs-cart_multivendor:4.3.7:*:*:ja:*:*:*:*","matchCriteriaId":"637065FC-883A-4E51-94B5-8F38F0574BCC"},{"vulnerable":true,"criteria":"cpe:2.3:a:cs-cart:cs-cart_multivendor:4.3.8:*:*:ja:*:*:*:*","matchCriteriaId":"5EBCC962-D3B4-4588-87EA-988CBD8EE7FD"},{"vulnerable":true,"criteria":"cpe:2.3:a:cs-cart:cs-cart_multivendor:4.3.9:*:*:ja:*:*:*:*","matchCriteriaId":"39E7A002-9015-4D75-AF02-21964DE6C0EE"},{"vulnerable":true,"criteria":"cpe:2.3:a:cs-cart:cs-cart_multivendor:4.3.10:*:*:ja:*:*:*:*","matchCriteriaId":"14591AE4-58B9-4F71-BA5E-A1C897979A35"}]}]}]},"legacy_mitre":{"record":{"CveYear":"2017","CveId":"10886","Ordinal":"1","Title":"CVE-2017-10886","CVE":"CVE-2017-10886","Year":"2017"},"notes":[{"CveYear":"2017","CveId":"10886","Ordinal":"1","NoteData":"Cross-site scripting vulnerability in CS-Cart Japanese Edition v4.3.10 and earlier (excluding v2 and v3), CS-Cart Multivendor Japanese Edition v4.3.10 and earlier (excluding v2 and v3) allows an attacker to inject arbitrary web script or HTML via unspecified vectors.","Type":"Description","Title":"CVE-2017-10886"},{"CveYear":"2017","CveId":"10886","Ordinal":"2","NoteData":"2017-11-17","Type":"Other","Title":"Published"},{"CveYear":"2017","CveId":"10886","Ordinal":"3","NoteData":"2017-11-17","Type":"Other","Title":"Modified"}]}}}