CVE Published: 05/03/2023 |
CVE Updated: 02/08/2024 |
CVE Year: 2023 Source: jpcert |
Vendor: EC-CUBE CO.,LTD. |
Product: EC-CUBE 4 series Status : PUBLISHED
CVE-2023-22838 Description
Cross-site scripting vulnerability in Product List Screen and Product Detail Screen of EC-CUBE 4.0.0 to 4.0.6-p2, EC-CUBE 4.1.0 to 4.1.2-p1, and EC-CUBE 4.2.0 allows a remote authenticated attacker to inject an arbitrary script.