4.8
CVSSv3

CVE-2018-0657

Published: 07/09/2018 Updated: 20/11/2018
CVSS v2 Base Score: 3.5 | Impact Score: 2.9 | Exploitability Score: 6.8
CVSS v3 Base Score: 4.8 | Impact Score: 2.7 | Exploitability Score: 1.7
Vector: AV:N/AC:M/Au:S/C:N/I:P/A:N

Vulnerability Summary

Cross-site scripting vulnerability in EC-CUBE Payment Module and GMO-PG Payment Module (PG Multi-Payment Service) for EC-CUBE (EC-CUBE Payment Module (2.12) version 3.5.23 and previous versions, EC-CUBE Payment Module (2.11) version 2.3.17 and previous versions, GMO-PG Payment Module (PG Multi-Payment Service) (2.12) version 3.5.23 and previous versions, and GMO-PG Payment Module (PG Multi-Payment Service) (2.11) version 2.3.17 and previous versions) allow an attacker with administrator rights to inject arbitrary web script or HTML via unspecified vectors.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

ec-cube ec-cube payment module

gmo-pg gmo-pg payment module