| [Japanese] | 
| JVNDB-2023-000043 | 
| Multiple vulnerabilities in MicroEngine Mailform | 
|
| 
 
MicroEngine Mailform provided by MicroEngine Inc. contains multiple vulnerabilities listed below.Yuji Tounai of Mitsui Bussan Secure Directions, Inc. and hibiki moriyama of STNet, Incorporated reported these vulnerabilities to IPA.Unrestricted upload of file with dangerous type (CWE-434) - CVE-2023-27397Path traversal (CWE-22) - CVE-2023-27507
 JPCERT/CC coordinated with the developer under Information Security Early Warning Partnership.
 | 
|
| 
 
  CVSS V3 Severity:Base Metrics 3.7 (Low) [IPA Score]
 
    Attack Vector: NetworkAttack Complexity: HighPrivileges Required: NoneUser Interaction: NoneScope: UnchangedConfidentiality Impact: NoneIntegrity Impact: LowAvailability Impact: None 
  CVSS V2 Severity:Base Metrics 4.3 (Medium) [IPA Score]
 
    Access Vector: NetworkAccess Complexity: MediumAuthentication: NoneConfidentiality Impact: NoneIntegrity Impact: PartialAvailability Impact: None 
  
The above CVSS base scores have been assigned for CVE-2023-27397
 | 
| 
 
 
  CVSS V3 Severity:Base Metrics 3.7 (Low) [IPA Score]
 
    Attack Vector: NetworkAttack Complexity: HighPrivileges Required: NoneUser Interaction: NoneScope: UnchangedConfidentiality Impact: NoneIntegrity Impact: LowAvailability Impact: None 
  CVSS V2 Severity:Base Metrics 4.3 (Medium) [IPA Score]
 
    Access Vector: NetworkAccess Complexity: MediumAuthentication: NoneConfidentiality Impact: NoneIntegrity Impact: PartialAvailability Impact: None 
The above CVSS base scores have been assigned for CVE-2023-27507
 | 
|
| 
 
	
 | 
| 
 
	MicroEngine Inc.
	
		MicroEngine Mailform version 1.1.0 to 1.1.8 | 
| 
 
	
 | 
|
| 
 
If the product's file upload function and server save option are enabled, a remote attacker may save an arbitrary file on the server and execute it.
 | 
|
| 
 
[Update the Software]Update to version 1.1.9 or later according to the information provided by the developer.
 
 [Apply workarounds]
 The developer also provides the workaround information regarding this issue.
 
 For more information, refer to the information provided by the developer.
 | 
|
| 
 
	MicroEngine Inc.
	
 | 
|
| 
 
	Path Traversal(CWE-22) [IPA Evaluation]No Mapping(CWE-Other) [IPA Evaluation] | 
|
| 
 
	CVE-2023-27397 CVE-2023-27507  | 
|
| 
 
	JVN : JVN#31701509 National Vulnerability Database (NVD) : CVE-2023-27397 National Vulnerability Database (NVD) : CVE-2023-27507  | 
|
| 
 
	[2023/05/10]Web page was published
[2024/05/24]References : Contents were added
 
 |