CVE Published: 22/06/2021 |
CVE Updated: 03/08/2024 |
CVE Year: 2021 Source: jpcert |
Vendor: EC-CUBE CO.,LTD. |
Product: EC-CUBE Business form output plugin (for EC-CUBE 3.0 series) Status : PUBLISHED
CVE-2021-20742 Description
Cross-site scripting vulnerability in EC-CUBE Business form output plugin (for EC-CUBE 3.0 series) versions prior to version 1.0.1 allows a remote attacker to inject an arbitrary script via unspecified vector.