Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2023-51011 | EC-CUBE 3 series (3.0.0 to 3.0.18-p6) and 4 series (4.0.0 to 4.0.6-p3, 4.1.0 to 4.1.2-p2, and 4.2.0 to 4.2.2) contain an arbitrary code execution vulnerability due to improper settings of the template engine Twig included in the product. As a result, arbitrary code may be executed on the server where the product is running by a user with an administrative privilege. |
No history.
Status: PUBLISHED
Assigner: jpcert
Published:
Updated: 2024-09-04T20:28:15.713Z
Reserved: 2023-10-27T08:05:25.926Z
Link: CVE-2023-46845
Updated: 2024-08-02T20:53:21.888Z
Status : Modified
Published: 2023-11-07T08:15:24.257
Modified: 2026-06-17T06:31:44.807
Link: CVE-2023-46845
No data.
OpenCVE Enrichment
No data.
-
CWE-94
Improper Control of Generation of Code ('Code Injection')
EUVD