| [Japanese] | 
| JVNDB-2023-000091 | 
| Multiple vulnerabilities in F-RevoCRM | 
|
| 
 
F-RevoCRM provided by ThinkingReed inc. contains multiple vulnerabilities listed below.
 * OS Command Injection (CWE-78) - CVE-2023-41149
 * Cross-site scripting vulnerability (CWE-79) - CVE-2023-41150
 
 Kentaro Ishii of GMO Cybersecurity by Ierae, Inc. reported these vulnerabilities to IPA.
 JPCERT/CC coordinated with the developer under Information Security Early Warning Partnership.
 | 
|
| 
 
  CVSS V3 Severity:Base Metrics 9.8 (Critical) [IPA Score]
 
    Attack Vector: NetworkAttack Complexity: LowPrivileges Required: NoneUser Interaction: NoneScope: UnchangedConfidentiality Impact: HighIntegrity Impact: HighAvailability Impact: High 
  CVSS V2 Severity:Base Metrics 7.5 (High) [IPA Score]
 
    Access Vector: NetworkAccess Complexity: LowAuthentication: NoneConfidentiality Impact: PartialIntegrity Impact: PartialAvailability Impact: Partial 
  
The above CVSS base scores have been assigned for CVE-2023-41149
 | 
| 
 
 
CVSS V3 Severity:
Base Metrics 5.4 (Medium) [IPA Score]
Attack Vector: NetworkAttack Complexity: LowPrivileges Required: LowUser Interaction: RequiredScope: ChangedConfidentiality Impact: LowIntegrity Impact: LowAvailability Impact: None 
CVSS V2 Severity:
Base Metrics 3.5 (Low) [IPA Score]
Access Vector: NetworkAccess Complexity: MediumAuthentication: SingleConfidentiality Impact: NoneIntegrity Impact: PartialAvailability Impact: None 
The above CVSS base scores have been assigned for CVE-2023-41150
 | 
|
| 
 
	
 | 
| 
 
	thinkingreed
	
		F-RevoCRM version 7.3.7 and version 7.3.8 (CVE-2023-41149)F-RevoCRM 7.3 series prior to version 7.3.8 (CVE-2023-41150) | 
| 
 
	
 | 
|
| 
 
  * An attacker who can access the product may execute an arbitrary OS command on the server where the product is running - CVE-2023-41149* An arbitrary script may be executed on the web browser of the user who is using the product - CVE-2023-41150
 | 
|
| 
 
[Apply the Patch]Apply the patch according to the information provided by the developer.
 | 
|
| 
 
	thinkingreed
	
 | 
|
| 
 
	OS Command Injection(CWE-78) [IPA Evaluation]Cross-site Scripting(CWE-79) [IPA Evaluation] | 
|
| 
 
	CVE-2023-41149 CVE-2023-41150  | 
|
| 
 
	JVN : JVN#78113802 National Vulnerability Database (NVD) : CVE-2023-41149 National Vulnerability Database (NVD) : CVE-2023-41150  | 
|
| 
 
	[2023/09/05]Web page was published
[2024/05/14]References : Contents were added
 
 |