Required CVE Record Information
Description
Cross-site scripting (XSS) vulnerability in the Cyber-Will Social-button Premium plugin before 1.1 for EC-CUBE 2.13.x allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
References 4 Total
- http://www.cyber-will.co.jp/SA_JVN_78482127
- https://www.ec-cube.net/products/detail.php?product_id=799
- jvndb.jvn.jp: JVNDB-2016-000048 third-party-advisory
- jvn.jp: JVN#78482127 third-party-advisory
Updated:
This container includes required additional information provided by the CVE Program for this vulnerability.
References 4 Total
- http://www.cyber-will.co.jp/SA_JVN_78482127 x_transferred
- https://www.ec-cube.net/products/detail.php?product_id=799 x_transferred
- jvndb.jvn.jp: JVNDB-2016-000048 third-party-advisoryx_transferred
- jvn.jp: JVN#78482127 third-party-advisoryx_transferred