VDB
Sign up
MEDIUM5.3

GHSA-pw97-6v74-9w3p

EC-CUBE improperly handles HTTP Host header values

Quick fix

GHSA-pw97-6v74-9w3p — ec-cube/ec-cube: upgrade to the fixed version with the command below.

composer require ec-cube/ec-cube:^4.1.2

Details

EC-CUBE 3.0.0 to 3.0.18-p3 and EC-CUBE 4.0.0 to 4.1.1 improperly handle HTTP Host header values, which may lead a remote unauthenticated attacker to direct the vulnerable version of EC-CUBE to send an Email with some forged reissue-password URL to EC-CUBE users.

Are you affected?

Enter the version of the package you're using.

Affected packages

Packagist/ec-cube/ec-cube
Introduced in: 3.0.0

No fixed version published yet for ec-cube/ec-cube (composer). Pin to a known-safe version or switch to an alternative.

Packagist/ec-cube/ec-cube
Introduced in: 4.0.0Fixed in: 4.1.2
Fixcomposer require ec-cube/ec-cube:^4.1.2

References