| [Japanese] | 
| JVNDB-2022-000012 | 
| Multiple vulnerabilities in phpUploader | 
|
| 
 
phpUploader provided by Dojin Club MICMNIS contains multiple vulnerabilities listed below. * Cross-site scripting (CWE-79) - CVE-2022-24435
 * SQL Injection (CWE-89) - CVE-2022-23986
 
 Toyama Taku reported these vulnerabilities to IPA.
 JPCERT/CC coordinated with the developer under Information Security Early Warning Partnership.
 | 
|
| 
 
  CVSS V3 Severity:Base Metrics 5.3 (Medium) [IPA Score]
 
    Attack Vector: NetworkAttack Complexity: LowPrivileges Required: NoneUser Interaction: NoneScope: UnchangedConfidentiality Impact: LowIntegrity Impact: NoneAvailability Impact: None 
  CVSS V2 Severity:Base Metrics 5.0 (Medium) [IPA Score]
 
    Access Vector: NetworkAccess Complexity: LowAuthentication: NoneConfidentiality Impact: PartialIntegrity Impact: NoneAvailability Impact: None 
  
The above CVSS base scores have been assigned for CVE-2022-23986
 | 
| 
 
 
 CVSS V3 Severity:Base Metrics 6.1 (Medium) [IPA Score]
 
Attack Vector: NetworkAttack Complexity: LowPrivileges Required: NoneUser Interaction: RequiredScope: ChangedConfidentiality Impact: LowIntegrity Impact: LowAvailability Impact: None 
CVSS V2 Severity:Base Metrics 4.3 (Medium) [IPA Score]
Access Vector: NetworkAccess Complexity: MediumAuthentication: NoneConfidentiality Impact: NoneIntegrity Impact: PartialAvailability Impact: None 
The above CVSS base scores have been assigned for CVE-2022-24435
 | 
|
| 
 
	
 | 
| 
 
	MICMNIS
	
		phpUploader v1.2 and earlier | 
| 
 
	
 | 
|
| 
 
* An arbitrary script may be executed on the web browser of the user who is accessing a website that uses the software - CVE-2022-24435* A remoter attacker may obtain the information in the database - CVE-2022-23986
 | 
|
| 
 
[Update the Software]Update the software to the latest version according to the information provided by the developer.
 | 
|
| 
 
	MICMNIS
	
 | 
|
| 
 
	Cross-site Scripting(CWE-79) [IPA Evaluation]SQL Injection(CWE-89) [IPA Evaluation] | 
|
| 
 
	CVE-2022-24435 CVE-2022-23986  | 
|
| 
 
	JVN : JVN#00095004 National Vulnerability Database (NVD) : CVE-2022-23986 National Vulnerability Database (NVD) : CVE-2022-24435  | 
|
| 
 
	[2022/02/17]Web page was published
 
 |