GHSA-r6qq-qc9m-98w2
GitHub Security Advisory
EC-CUBE Cross-site scripting vulnerability
✓ GitHub Reviewed
MODERATE
Has CVE
Advisory Details
Cross-site scripting vulnerability in EC-CUBE EC-CUBE 4.0.0 to 4.0.5-p1 (EC-CUBE 4 series) allows a remote attacker to inject an arbitrary script by leading an administrator or a user to a specially crafted page and to perform a specific operation.
Affected Packages
Packagist
ec-cube/ec-cube
Affected versions:
4.0.0
(fixed in 4.0.6)
Related CVEs
Key Information
5.0
/10
Dataset
Last updated: July 9, 2025 6:27 AM
Data from GitHub Advisory Database. This information is provided for research and educational purposes.