Published: 2019/08/07  Last Updated: 2019/08/07

Information from IPLOGIC CO.,LTD.

Vulnerability ID:JVN#29343839
Title:EC-CUBE plugin "Amazon Pay Plugin 2.12,2.13" vulnerable to cross-site scripting
Status:Vulnerable

This is a statement from the vendor itself with no modification by JPCERT/CC.

We have already released the plug-in which this vulnerability is fixed.
https://www.ec-cube.net/products/detail.php?product_id=1602
In addition, the customers have been notified of the way to fix the bug by emailing.