[Japanese]
|
JVNDB-2023-000007
|
WordPress plugin "Welcart e-Commerce" vulnerable to directory traversal
|
WordPress plugin "Welcart e-Commerce" provided by Collne Inc. contains a directory traversal vulnerability (CWE-22).
Masato Ikeda of Mitsui Bussan Secure Directions, Inc. and Takeshi Suzuki reported this vulnerability to IPA.
JPCERT/CC coordinated with the developer under Information Security Early Warning Partnership.
|
CVSS V3 Severity: Base Metrics 7.5 (High) [IPA Score]
- Attack Vector: Network
- Attack Complexity: Low
- Privileges Required: None
- User Interaction: None
- Scope: Unchanged
- Confidentiality Impact: High
- Integrity Impact: None
- Availability Impact: None
CVSS V2 Severity: Base Metrics 5.0 (Medium) [IPA Score]
- Access Vector: Network
- Access Complexity: Low
- Authentication: None
- Confidentiality Impact: Partial
- Integrity Impact: None
- Availability Impact: None
|
|
Collne Inc.
- Welcart e-Commerce versions 2.6.0 to 2.8.5
|
|
Arbitrary files on the server may be viewed by a remote attacker.
|
[Update the plugin]
Update the plugin according to the information provided by the developer.
The developer has released the following version that addresses the vulnerability.
* Welcart e-Commerce 2.8.6 or later
|
Collne Inc.
|
- Path Traversal(CWE-22) [IPA Evaluation]
|
- CVE-2022-4140
|
- JVN : JVN#31073333
- National Vulnerability Database (NVD) : CVE-2022-4140
- Related document : Welcart e-Commerce < 2.8.5 - Unauthenticated Arbitrary File Access
|
- [2023/01/17]
Web page was published
|