{"id":"GHSA-wgvv-5396-ggvj","summary":"EC-CUBE XSS Vulnerabilities","details":"Multiple cross-site scripting (XSS) vulnerabilities in (1) `data/Smarty/templates/default/list.tpl` and (2) `data/Smarty/templates/default/campaign/bloc/cart_tag.tpl` in EC-CUBE before 2.4.4 allow remote attackers to inject arbitrary web script or HTML via unspecified vectors.","aliases":["CVE-2011-0451"],"modified":"2024-01-15T21:26:53.850575Z","published":"2022-05-17T02:02:18Z","database_specific":{"cwe_ids":["CWE-79"],"severity":"MODERATE","github_reviewed":true,"github_reviewed_at":"2024-01-15T20:53:35Z","nvd_published_at":"2011-02-03T16:00:00Z"},"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2011-0451"},{"type":"WEB","url":"https://github.com/EC-CUBE/ec-cube/commit/8ef6541fc66b86d40a4333ec1608be3191c5e463"},{"type":"WEB","url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/65079"},{"type":"PACKAGE","url":"https://github.com/EC-CUBE/ec-cube"},{"type":"WEB","url":"https://web.archive.org/web/20200229005109/http://www.securityfocus.com/bid/46100"},{"type":"WEB","url":"http://jvn.jp/en/jp/JVN84393059/index.html"},{"type":"WEB","url":"http://jvndb.jvn.jp/en/contents/2011/JVNDB-2011-000011.html"},{"type":"WEB","url":"http://svn.ec-cube.net/open_trac/changeset/18742"},{"type":"WEB","url":"http://www.ec-cube.net/info/weakness/weakness.php?id=36"}],"affected":[{"package":{"name":"ec-cube/ec-cube","ecosystem":"Packagist","purl":"pkg:composer/ec-cube/ec-cube"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"2.4.4"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/05/GHSA-wgvv-5396-ggvj/GHSA-wgvv-5396-ggvj.json"}}],"schema_version":"1.9.0"}