EC-CUBE Directory traversal vulnerability
Low severity
GitHub Reviewed
Published
Sep 28, 2022
to the GitHub Advisory Database
•
Updated Apr 25, 2024
Package
Affected versions
>= 3.0.0, <= 3.0.18-p4
>= 4.0.0, <= 4.1.2
Patched versions
None
Description
Published by the National Vulnerability Database
Sep 27, 2022
Published to the GitHub Advisory Database
Sep 28, 2022
Last updated
Apr 25, 2024
Reviewed
Apr 25, 2024
Directory traversal vulnerability in EC-CUBE 3 series (EC-CUBE 3.0.0 to 3.0.18-p4 ) and EC-CUBE 4 series (EC-CUBE 4.0.0 to 4.1.2) allows a remote authenticated attacker with an administrative privilege to obtain the product's directory structure information.
References