Início
Tendências
Vulnerabilidades
Notícias
Pesquisadores
Por que dbugs?

三浦 剛

Pesquisador de株式会社エヌ・エフ・ラボラトリーズ
#38309de 53,639
7.2CVSS total
Vulnerabilidades · 1
PT-2023-30241
7.2
2023-11-07
Twig · Twig · CVE-2023-46845
**Name of the Vulnerable Software and Affected Versions** EC-CUBE versions 3.0.0 through 3.0.18-p6 EC-CUBE versions 4.0.0 through 4.0.6-p3 EC-CUBE versions 4.1.0 through 4.1.2-p2 EC-CUBE versions 4.2.0 through 4.2.2 **Description** The issue is due to improper settings of the `template engine Twig` included in the product, allowing arbitrary code execution on the server where the product is running by a user with administrative privilege. **Recommendations** For versions 3.0.0 through 3.0.18-p6, update the template engine settings to prevent arbitrary code execution. For versions 4.0.0 through 4.0.6-p3, update the template engine settings to prevent arbitrary code execution. For versions 4.1.0 through 4.1.2-p2, update the template engine settings to prevent arbitrary code execution. For versions 4.2.0 through 4.2.2, update the template engine settings to prevent arbitrary code execution.