# EC-CUBE XSS Flaw Exploited in the Wild

Published: 2021-05-09 · Severity: medium · Sectors: retail
Canonical: https://vorant.io/reports/771932fa-ef59-5d3c-a484-1ad4a51a3a2d/ec-cube-xss-flaw-exploited-in-the-wild

> A cross-site scripting vulnerability in EC-CUBE's admin panel is being actively exploited, letting attackers run scripts in admin browsers.

IPA (Japan) issued an advisory for EC-CUBE, an open-source e-commerce site-building platform developed by EC-CUBE Co., Ltd. The flaw is a cross-site scripting (XSS) vulnerability in the product's administrative screen: an attacker can inject a script into specific input fields on an EC site built with the vulnerable product, causing arbitrary script execution in the browser of the site's administrator when they view the affected page.

The developer has confirmed that attacks exploiting this vulnerability have already been observed in the wild, prompting IPA to urge site operators to apply developer-provided updates or hotfix patches as soon as possible. CVSS v3 base score is rated 7.1 (important) and CVSS v2 at 6.8 (warning). No specific affected version list or patch details were included in the source text beyond the recommendation to update.

## Mentioned in this report

- Vulnerabilities: CVE-2021-20717

Source reporting: https://www.ipa.go.jp/archive/security/security-alert/2021/20210510-jvn.html

---

This is the free public brief from Vorant Threat Intelligence. When citing, attribute "Vorant" and link https://vorant.io/reports/771932fa-ef59-5d3c-a484-1ad4a51a3a2d/ec-cube-xss-flaw-exploited-in-the-wild.
Full IOC sets, deployable detections, the entity graph, TAXII 2.1 feed and real-time alerts: https://vorant.io/signup
