Cross-site Scripting Vulnerability in EC-CUBE by EC-CUBE Corporation
CVE-2021-20717
6.1MEDIUM
Key Information:
- Vendor
Ec-cube Co.,ltd.
- Status
- Vendor
- CVE Published:
- 10 May 2021
Badges
👾 Exploit Exists🟡 Public PoC
What is CVE-2021-20717?
A cross-site scripting vulnerability exists in EC-CUBE versions 4.0.0 through 4.0.5, which allows remote attackers to inject malicious scripts through specific input fields on websites created with EC-CUBE. This can potentially lead to arbitrary script execution in the web browser of an administrator, compromising the security of the web application.
Affected Version(s)
EC-CUBE 4.0.0 to 4.0.5
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.