[Japanese]
|
JVNDB-2011-000066
|
BaserCMS vulnerable to access restriction
|
BaserCMS contains a vulnerability in access restriction.
BaserCMS is an open-source Contents Management System (CMS). BaserCMS contains a vulnerability in access restriction where adding a user in the user group "operators" which is created by default when BaserCMS is installed.
Masako Ohno reported this vulnerability to IPA.
JPCERT/CC coordinated with the developer under Information Security Early Warning Partnership.
|
CVSS V2 Severity: Base Metrics 4.9 (Medium) [IPA Score]
- Access Vector: Network
- Access Complexity: Medium
- Authentication: Single Instance
- Confidentiality Impact: Partial
- Integrity Impact: Partial
- Availability Impact: None
|
|
baserCMS Users Community
- baserCMS 1.6.11.4 and earlier
|
|
Users without administrative privileges may obtain administrative privileges or alter the information of administrators.
|
[Update the software]
Update to the latest version according to the information provided by the developer.
[Apply a patch]
Apply the appropriate patch according to the information provided by the developer.
[Apply a workaround]
The following workaround may mitigate the affects of this vulnerability.
* Do not use the default user group "operators"
|
baserCMS Users Community
|
- Permissions(CWE-264) [IPA Evaluation]
|
- CVE-2011-2674
|
- JVN : JVN#16617002
- National Vulnerability Database (NVD) : CVE-2011-2674
|
- [2011/09/30]
Web page published
|