Vulnerability Details CVE-2023-46845
EC-CUBE 3 series (3.0.0 to 3.0.18-p6) and 4 series (4.0.0 to 4.0.6-p3, 4.1.0 to 4.1.2-p2, and 4.2.0 to 4.2.2) contain an arbitrary code execution vulnerability due to improper settings of the template engine Twig included in the product. As a result, arbitrary code may be executed on the server where the product is running by a user with an administrative privilege.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.012
EPSS Ranking 77.9%
CVSS Severity
CVSS v3 Score 7.2
Products affected by CVE-2023-46845
-
cpe:2.3:a:ec-cube:ec-cube:3.0.0
-
cpe:2.3:a:ec-cube:ec-cube:3.0.1
-
cpe:2.3:a:ec-cube:ec-cube:3.0.10
-
cpe:2.3:a:ec-cube:ec-cube:3.0.11
-
cpe:2.3:a:ec-cube:ec-cube:3.0.12
-
cpe:2.3:a:ec-cube:ec-cube:3.0.13
-
cpe:2.3:a:ec-cube:ec-cube:3.0.14
-
cpe:2.3:a:ec-cube:ec-cube:3.0.15
-
cpe:2.3:a:ec-cube:ec-cube:3.0.16
-
cpe:2.3:a:ec-cube:ec-cube:3.0.17
-
cpe:2.3:a:ec-cube:ec-cube:3.0.18
-
cpe:2.3:a:ec-cube:ec-cube:3.0.2
-
cpe:2.3:a:ec-cube:ec-cube:3.0.3
-
cpe:2.3:a:ec-cube:ec-cube:3.0.4
-
cpe:2.3:a:ec-cube:ec-cube:3.0.5
-
cpe:2.3:a:ec-cube:ec-cube:3.0.6
-
cpe:2.3:a:ec-cube:ec-cube:3.0.7
-
cpe:2.3:a:ec-cube:ec-cube:3.0.8
-
cpe:2.3:a:ec-cube:ec-cube:3.0.9
-
cpe:2.3:a:ec-cube:ec-cube:4.0.0
-
cpe:2.3:a:ec-cube:ec-cube:4.0.1
-
cpe:2.3:a:ec-cube:ec-cube:4.0.2
-
cpe:2.3:a:ec-cube:ec-cube:4.0.3
-
cpe:2.3:a:ec-cube:ec-cube:4.0.5
-
cpe:2.3:a:ec-cube:ec-cube:4.0.6
-
cpe:2.3:a:ec-cube:ec-cube:4.1.0
-
cpe:2.3:a:ec-cube:ec-cube:4.1.1
-
cpe:2.3:a:ec-cube:ec-cube:4.1.2
-
cpe:2.3:a:ec-cube:ec-cube:4.2.0