Vulnerabilities > EC Cube

DATE CVE VULNERABILITY TITLE RISK
2022-02-24 CVE-2022-21179 Cross-Site Request Forgery (CSRF) vulnerability in Ec-Cube E-Mail Newsletter Management
Cross-site request forgery (CSRF) vulnerability in EC-CUBE plugin 'Mail Magazine Management Plugin' ver4.0.0 to 4.1.1 (for EC-CUBE 4 series) and ver1.0.0 to 1.0.4 (for EC-CUBE 3 series) allows a remote unauthenticated attacker to hijack the authentication of an administrator via a specially crafted page, and Mail Magazine Templates and/or transmitted history information may be deleted unintendedly.
network
ec-cube CWE-352
4.3
2022-02-24 CVE-2022-25355 Missing Authorization vulnerability in Ec-Cube
EC-CUBE 3.0.0 to 3.0.18-p3 and EC-CUBE 4.0.0 to 4.1.1 improperly handle HTTP Host header values, which may lead a remote unauthenticated attacker to direct the vulnerable version of EC-CUBE to send an Email with some forged reissue-password URL to EC-CUBE users.
network
low complexity
ec-cube CWE-862
5.0
2021-11-24 CVE-2021-20841 Incorrect Authorization vulnerability in Ec-Cube
Improper access control in Management screen of EC-CUBE 2 series 2.11.2 to 2.17.1 allows a remote authenticated attacker to bypass access restriction and to alter System settings via unspecified vectors.
network
low complexity
ec-cube CWE-863
4.0
2021-11-24 CVE-2021-20842 Cross-Site Request Forgery (CSRF) vulnerability in Ec-Cube
Cross-site request forgery (CSRF) vulnerability in EC-CUBE 2 series 2.11.0 to 2.17.1 allows a remote attacker to hijack the authentication of Administrator and delete Administrator via a specially crafted web page.
network
ec-cube CWE-352
4.3
2021-07-01 CVE-2021-20778 Unspecified vulnerability in Ec-Cube 4.0.6
Improper access control vulnerability in EC-CUBE 4.0.6 (EC-CUBE 4 series) allows a remote attacker to bypass access restriction and obtain sensitive information via unspecified vectors.
network
low complexity
ec-cube
5.0
2021-06-28 CVE-2021-20750 Cross-site Scripting vulnerability in Ec-Cube
Cross-site scripting vulnerability in EC-CUBE EC-CUBE 3.0.0 to 3.0.18-p2 (EC-CUBE 3 series) and EC-CUBE 4.0.0 to 4.0.5-p1 (EC-CUBE 4 series) allows a remote attacker to inject an arbitrary script by leading an administrator or a user to a specially crafted page and to perform a specific operation.
network
ec-cube CWE-79
4.3
2021-06-28 CVE-2021-20751 Cross-site Scripting vulnerability in Ec-Cube
Cross-site scripting vulnerability in EC-CUBE EC-CUBE 4.0.0 to 4.0.5-p1 (EC-CUBE 4 series) allows a remote attacker to inject an arbitrary script by leading an administrator or a user to a specially crafted page and to perform a specific operation.
network
ec-cube CWE-79
4.3
2021-06-22 CVE-2021-20735 Cross-site Scripting vulnerability in Ec-Cube products
Cross-site scripting vulnerability in ETUNA EC-CUBE plugins (Delivery slip number plugin (3.0 series) 1.0.10 and earlier, Delivery slip number csv bulk registration plugin (3.0 series) 1.0.8 and earlier, and Delivery slip number mail plugin (3.0 series) 1.0.8 and earlier) allows remote attackers to inject an arbitrary script by executing a specific operation on the management page of EC-CUBE.
network
ec-cube CWE-79
4.3
2021-06-22 CVE-2021-20742 Cross-site Scripting vulnerability in Ec-Cube Business Form Output
Cross-site scripting vulnerability in EC-CUBE Business form output plugin (for EC-CUBE 3.0 series) versions prior to version 1.0.1 allows a remote attacker to inject an arbitrary script via unspecified vector.
network
ec-cube CWE-79
4.3
2021-06-22 CVE-2021-20743 Cross-site Scripting vulnerability in Ec-Cube Email Newsletters Management
Cross-site scripting vulnerability in EC-CUBE Email newsletters management plugin (for EC-CUBE 3.0 series) versions prior to version 1.0.4 allows a remote attacker to inject an arbitrary script by leading a user to a specially crafted page and to perform a specific operation.
network
ec-cube CWE-79
4.3