[Japanese] | |
JVNDB-2024-000081 | |
EC-CUBE plugin (for EC-CUBE 4 series) "EC-CUBE Web API Plugin" vulnerable to stored cross-site scripting | |
Overview | |
EC-CUBE plugin (for EC-CUBE 4 series) "EC-CUBE Web API Plugin" provided by EC-CUBE CO.,LTD. contains a stored cross-site scripting vulnerability (CWE-79) in OAuth Management feature. | |
CVSS Severity (What is CVSS?) | |
CVSS V3 Severity:
Base Metrics 4.8 (Medium) [IPA Score]
| |
Affected Products | |
| |
EC-CUBE CO.,LTD. | |
| |
Impact | |
When there are multiple users using OAuth Management feature and one of them inputs some crafted value on the OAuth Management page, an arbitrary script may be executed on the web browser of the other user who accessed the management page. | |
Solution | |
[Update the plugin] | |
Vendor Information | |
EC-CUBE CO.,LTD. | |
CWE (What is CWE?) | |
| |
CVE (What is CVE?) | |
| |
References | |
| |
Revision History | |
|
Date Public | 2024/07/30 |
Date First Published | 2024/07/30 |
Date Last Updated | 2024/07/30 |