VORANT. Threat Intelligence Sign in Get the full feed

EC-CUBE XSS Flaw Exploited in the Wild

medium vulnerability retail

A cross-site scripting vulnerability in EC-CUBE's admin panel is being actively exploited, letting attackers run scripts in admin browsers.

IPA (Japan) issued an advisory for EC-CUBE, an open-source e-commerce site-building platform developed by EC-CUBE Co., Ltd. The flaw is a cross-site scripting (XSS) vulnerability in the product's administrative screen: an attacker can inject a script into specific input fields on an EC site built with the vulnerable product, causing arbitrary script execution in the browser of the site's administrator when they view the affected page.

The developer has confirmed that attacks exploiting this vulnerability have already been observed in the wild, prompting IPA to urge site operators to apply developer-provided updates or hotfix patches as soon as possible. CVSS v3 base score is rated 7.1 (important) and CVSS v2 at 6.8 (warning). No specific affected version list or patch details were included in the source text beyond the recommendation to update.

Mentioned in this report

Vulnerabilities CVE-2021-20717

Source reporting: https://www.ipa.go.jp/archive/security/security-alert/2021/20210510-jvn.html

This is the public brief

Subscribers see the full picture: extracted IOCs, ready-to-deploy detections (Sigma, Splunk, KQL, Elastic, YARA, Suricata), the entity graph, TAXII 2.1 feed and real-time alerts matched to your sectors.

Start free