[Japanese]
|
JVNDB-2018-000045
|
Multiple vulnerabilities in WordPress plugin "Ultimate Member"
|
The WordPress plugin "Ultimate Member" provided by Ultimate Member contains multiple vulnerabilities listed below.
* Cross-site Scripting (CWE-79) - CVE-2018-0585
* Directory Traversal in the shortcodes function (CWE-22) - CVE-2018-0586
* Arbitrary File Upload (CWE-434) - CVE-2018-0587
* Directory Traversal in the AJAX function (CWE-22) - CVE-2018-0588
* Access Restriction Bypass in the "Forms" page (CWE-284) - CVE-2018-0589
* Access Restriction Bypass due to an issue in processing "Role" (CWE-284) - CVE-2018-0590
Gen Sato of Mitsui Bussan Secure Directions, Inc. reported this vulnerability to IPA.
JPCERT/CC coordinated with the developer under Information Security Early Warning Partnership.
|
CVSS V3 Severity: Base Metrics 7.2 (High) [IPA Score]
- Attack Vector: Network
- Attack Complexity: Low
- Privileges Required: None
- User Interaction: None
- Scope: Changed
- Confidentiality Impact: None
- Integrity Impact: Low
- Availability Impact: Low
CVSS V2 Severity: Base Metrics 6.4 (Medium) [IPA Score]
- Access Vector: Network
- Access Complexity: Low
- Authentication: None
- Confidentiality Impact: None
- Integrity Impact: Partial
- Availability Impact: Partial
The above CVSS base scores have been assigned for CVE-2018-0588
|
CVSS V3 Severity:
Base Metrics:
5.4 (Medium) [IPA Score]
-
Attack Vector: Network
-
Attack Complexity: Low
-
Privileges Required: Low
-
User Interaction: Required: Required
-
Scope: Changed
-
Confidentiality Impact: Low
-
Integrity Impact: Low
-
Availability Impact: None
CVSS V2 Severity:Base Metrics:
4.0 (Low)
[IPA Score]
-
Access Vector: Network
-
Access Complexity: Low
-
Authentication: Single
-
Confidentiality Impact: None
-
Integrity Impact: Partial
-
Availability Impact: None
The above CVSS base scores have been assigned for CVE-2018-0585
|
CVSS V3 Severity:
Base Metrics:
5.0 (Medium) [IPA Score]
-
Attack Vector: Network
-
Attack Complexity: Low
-
Privileges Required: Low
-
User Interaction: Required: None
-
Scope: Changed
-
Confidentiality Impact: Low
-
Integrity Impact: None
-
Availability Impact: None
CVSS V2 Severity:Base Metrics:
4.0 (Low)
[IPA Score]
-
Access Vector: Network
-
Access Complexity: Low
-
Authentication: Single
-
Confidentiality Impact: Partial
-
Integrity Impact: None
-
Availability Impact: None
The above CVSS base scores have been assigned for CVE-2018-0586
|
CVSS V3 Severity:
Base Metrics:
5.3 (Medium) [IPA Score]
-
Attack Vector: Network
-
Attack Complexity: Low
-
Privileges Required: None
-
User Interaction: Required: None
-
Scope: Unchanged
-
Confidentiality Impact: None
-
Integrity Impact: Low
-
Availability Impact: None
CVSS V2 Severity:Base Metrics:
5.0 (Medium)
[IPA Score]
-
Access Vector: Network
-
Access Complexity: Low
-
Authentication: None
-
Confidentiality Impact: None
-
Integrity Impact: Partial
-
Availability Impact: None
The above CVSS base scores have been assigned for CVE-2018-0587
|
CVSS V3 Severity:
Base Metrics:
4.3 (Medium) [IPA Score]
-
Attack Vector: Network
-
Attack Complexity: Low
-
Privileges Required: Low
-
User Interaction: Required: None
-
Scope: Unchanged
-
Confidentiality Impact: Low
-
Integrity Impact: None
-
Availability Impact: None
CVSS V2 Severity:Base Metrics:
4.0 (Low)
[IPA Score]
-
Access Vector: Network
-
Access Complexity: Low
-
Authentication: Single
-
Confidentiality Impact: Partial
-
Integrity Impact: None
-
Availability Impact: None
The above CVSS base scores have been assigned for CVE-2018-0589
|
CVSS V3 Severity:
Base Metrics:
4.3 (Medium) [IPA Score]
-
Attack Vector: Network
-
Attack Complexity: Low
-
Privileges Required: Low
-
User Interaction: Required: None
-
Scope: Unchanged
-
Confidentiality Impact: Low
-
Integrity Impact: None
-
Availability Impact: None
CVSS V2 Severity:Base Metrics:
4.0 (Low)
[IPA Score]
-
Access Vector: Network
-
Access Complexity: Low
-
Authentication: Single
-
Confidentiality Impact: Partial
-
Integrity Impact: None
-
Availability Impact: None
The above CVSS base scores have been assigned for CVE-2018-0590
|
|
Ultimate Member Group Ltd
- Ultimate Member prior to version 2.0.4
|
|
* An arbitrary script may be executed on the user's web browser - CVE-2018-0585
* Arbitrary local files on the server may be accessed by a logged-in user - CVE-2018-0586
* An arbitrary image file can be uploaded by a remote attacker, which may be used for unauthorized file sharing - CVE-2018-0587
* A remote attacker may delete arbitrary files on the server - CVE-2018-0588
* A user with the Author role may add a new form - CVE-2018-0589
* Profiles for other users may be modified by a logged-in user - CVE-2018-0590
|
[Update the plugin]
Update the plugin according to the information provided by the developer.
|
Ultimate Member Group Ltd
|
- Improper Input Validation(CWE-20) [IPA Evaluation]
- Path Traversal(CWE-22) [IPA Evaluation]
- Permissions(CWE-264) [IPA Evaluation]
- Cross-site Scripting(CWE-79) [IPA Evaluation]
|
- CVE-2018-0585
- CVE-2018-0586
- CVE-2018-0587
- CVE-2018-0588
- CVE-2018-0589
- CVE-2018-0590
|
- JVN : JVN#28804532
- National Vulnerability Database (NVD) : CVE-2018-0585
- National Vulnerability Database (NVD) : CVE-2018-0586
- National Vulnerability Database (NVD) : CVE-2018-0587
- National Vulnerability Database (NVD) : CVE-2018-0588
- National Vulnerability Database (NVD) : CVE-2018-0589
- National Vulnerability Database (NVD) : CVE-2018-0590
|
- [2018/05/10]
Web page was published
- [2018/08/30]
References : Contents were added
|