216.73.216.197

CVE-2024-41141

· Published 30/07/2024 09:15 · Modified 30/07/2024 13:32

Labels: CVE-2024-41141 2024-07-30CVE-2024-41141[email protected]

Essential information

Published
30/07/2024 09:15
Modified
30/07/2024 13:32
Author
Creator
CISA KEV
No
CWE

Description

Stored cross-site scripting vulnerability exists in EC-CUBE Web API Plugin. When there are multiple users using OAuth Management feature and one of them inputs some crafted value on the OAuth Management page, an arbitrary script may be executed on the web browser of the other user who accessed the management page.

NVD status

Status
Awaiting Analysis — CVE has been recently published to the CVE List and has been received by the NVD.
Source
[email protected]
NVD
View on NVD

References