Acceptance of extraneous untrusted data with trusted data vulnerability exists in EC-CUBE 4 series. If this vulnerability is exploited, an attacker who obtained the administrative privilege may install an arbitrary PHP package. If the obsolete versions of PHP packages are installed, the product may be affected by some known vulnerabilities.
                
            References
                    Configurations
                    No configuration.
History
                    18 Mar 2025, 19:15
| Type | Values Removed | Values Added | 
|---|---|---|
| CWE | CWE-349 | 
21 Nov 2024, 09:33
| Type | Values Removed | Values Added | 
|---|---|---|
| References | () https://jvn.jp/en/jp/JVN48324254/ - | |
| References | () https://www.ec-cube.net/info/weakness/20240701/index.php - | 
01 Aug 2024, 13:59
| Type | Values Removed | Values Added | 
|---|---|---|
| CVSS | 
        v2 :  v3 :  | 
    
        v2 : unknown
         v3 : 7.2  | 
30 Jul 2024, 13:32
| Type | Values Removed | Values Added | 
|---|---|---|
| Summary | 
        
        
  | 
30 Jul 2024, 09:15
| Type | Values Removed | Values Added | 
|---|---|---|
| New CVE | 
Information
                Published : 2024-07-30 09:15
Updated : 2025-03-18 19:15
NVD link : CVE-2024-41924
Mitre link : CVE-2024-41924
CVE.ORG link : CVE-2024-41924
JSON object : View
Products Affected
                No product.
CWE
                
                    
                        
                        CWE-349
                        
            Acceptance of Extraneous Untrusted Data With Trusted Data
