Loading HuntDB...

GHSA-m7gf-q6fm-2r43

GitHub Security Advisory

⚠ Unreviewed MODERATE Has CVE

Advisory Details

EC-CUBE 2.11.0 to 2.17.2-p1 contain a cross-site scripting vulnerability in "mail/template" and "products/product" of Management page.
If this vulnerability is exploited, an arbitrary script may be executed on the web browser of the other administrator or the user who accessed the website using the product.

Related CVEs

Key Information

GHSA ID
GHSA-m7gf-q6fm-2r43
Published
August 17, 2023 9:30 AM
Last Modified
April 4, 2024 7:01 AM
CVSS Score
5.0 /10
Primary Ecosystem
Unknown
Primary Package
Unknown
GitHub Reviewed
✗ No

Dataset

Last updated: July 10, 2025 6:27 AM

Data from GitHub Advisory Database. This information is provided for research and educational purposes.