MEDIUM5.3
GHSA-pw97-6v74-9w3p
EC-CUBE improperly handles HTTP Host header values
Quick fix
GHSA-pw97-6v74-9w3p — ec-cube/ec-cube: upgrade to the fixed version with the command below.
composer require ec-cube/ec-cube:^4.1.2Details
EC-CUBE 3.0.0 to 3.0.18-p3 and EC-CUBE 4.0.0 to 4.1.1 improperly handle HTTP Host header values, which may lead a remote unauthenticated attacker to direct the vulnerable version of EC-CUBE to send an Email with some forged reissue-password URL to EC-CUBE users.
Are you affected?
Enter the version of the package you're using.
Affected packages
Packagist/ec-cube/ec-cube
Introduced in:
3.0.0No fixed version published yet for ec-cube/ec-cube (composer). Pin to a known-safe version or switch to an alternative.
Packagist/ec-cube/ec-cube
Introduced in:
4.0.0Fixed in: 4.1.2Fix
composer require ec-cube/ec-cube:^4.1.2