[Japanese]
|
JVNDB-2023-000106
|
Multiple vulnerabilities in baserCMS
|
baserCMS provided by baserCMS Users Community contains multiple vulnerabilities listed below.- Stored cross-site scripting vulnerability (CWE-79) - CVE-2023-29009
- Reflected cross-site scripting vulnerability (CWE-79) - CVE-2023-43647
- Directory traversal vulnerability (CWE-22) - CVE-2023-43648
- Cross-site request forgery vulnerability (CWE-352) - CVE-2023-43649
- Arbitrary file upload vulnerability (CWE-434) - CVE-2023-43792
CVE-2023-29009
Kyohei Ota reported this vulnerability to IPA.
JPCERT/CC coordinated with the developer under Information Security Early Warning Partnership.
CVE-2023-43647, CVE-2023-43648, CVE-2023-43649, CVE-2023-43792
Shiga Takuma of BroadBand Security, Inc reported these vulnerabilities to IPA.
JPCERT/CC coordinated with the developer under Information Security Early Warning Partnership.
|
CVSS V3 Severity: Base Metrics 6.3 (Medium) [IPA Score]
- Attack Vector: Network
- Attack Complexity: Low
- Privileges Required: None
- User Interaction: Required
- Scope: Unchanged
- Confidentiality Impact: Low
- Integrity Impact: Low
- Availability Impact: Low
CVSS V2 Severity: Base Metrics 6.8 (Medium) [IPA Score]
- Access Vector: Network
- Access Complexity: Medium
- Authentication: None
- Confidentiality Impact: Partial
- Integrity Impact: Partial
- Availability Impact: Partial
The above CVSS base scores have been assigned for CVE-2023-43649
|
CVSS V3 Severity:
Base Metrics 5.4 (Medium) [IPA Score]
- Attack Vector: Network
- Attack Complexity: Low
- Privileges Required: Low
- User Interaction: Required
- Scope: Changed
- Confidentiality Impact: Low
- Integrity Impact: Low
- Availability Impact: None
CVSS V2 Severity:
Base Metrics 3.5 (Low) [IPA Score]
- Access Vector: Network
- Access Complexity: Medium
- Authentication: Single
- Confidentiality Impact: None
- Integrity Impact: Partial
- Availability Impact: None
The above CVSS base scores have been assigned for CVE-2023-29009
|
CVSS V3 Severity:
Base Metrics 6.1 (Medium) [IPA Score]
- Attack Vector: Network
- Attack Complexity: Low
- Privileges Required: None
- User Interaction: Required
- Scope: Changed
- Confidentiality Impact: Low
- Integrity Impact: Low
- Availability Impact: None
CVSS V2 Severity:
Base Metrics 2.6 (Low) [IPA Score]
- Access Vector: Network
- Access Complexity: High
- Authentication: None
- Confidentiality Impact: None
- Integrity Impact: Partial
- Availability Impact: None
The above CVSS base scores have been assigned for CVE-2023-43647
|
CVSS V3 Severity:
Base Metrics 4.9 (Medium) [IPA Score]
- Attack Vector: Network
- Attack Complexity: Low
- Privileges Required: High
- User Interaction: None
- Scope: Unchanged
- Confidentiality Impact: High
- Integrity Impact: None
- Availability Impact: None
CVSS V2 Severity:
Base Metrics 4.0 (Medium) [IPA Score]
- Access Vector: Network
- Access Complexity: Low
- Authentication: Single
- Confidentiality Impact: Partial
- Integrity Impact: None
- Availability Impact: None
The above CVSS base scores have been assigned for CVE-2023-43648
|
CVSS V3 Severity:
Base Metrics 5.3 (Medium) [IPA Score]
- Attack Vector: Network
- Attack Complexity: Low
- Privileges Required: None
- User Interaction: None
- Scope: Unchanged
- Confidentiality Impact: None
- Integrity Impact: Low
- Availability Impact: None
CVSS V2 Severity:
Base Metrics 5.0 (Medium) [IPA Score]
- Access Vector: Network
- Access Complexity: Low
- Authentication: None
- Confidentiality Impact: None
- Integrity Impact: Partial
- Availability Impact: None
The above CVSS base scores have been assigned for CVE-2023-43792
|
|
baserCMS Users Community
- baserCMS 4.7.8 and earlier (CVE-2023-29009, CVE-2023-43647, CVE-2023-43648, CVE-2023-43649)
- baserCMS 4.6.0 to 4.7.6 (CVE-2023-43792)
|
|
- An arbitrary script may be executed on the web browser of the user who is accessing the administrative page of the product - CVE-2023-29009, CVE-2023-43647
- A user who is accessing the administrative page of the product may obtain arbitrary files on the product - CVE-2023-43648
- If a user views a malicious page while logging in the administrative page of the product, arbitrary code may be executed on the server - CVE-2023-43649
- A remote attacker may upload an arbitrary file to the product - CVE-2023-43792
|
[Update the Software]
Update the software to the latest version according to the information provided by the developer.
The developer has released the following versions that contain fixes for the vulnerabilities.
CVE-2023-29009, CVE-2023-43647, CVE-2023-43648, CVE-2023-43649
CVE-2023-43792
|
baserCMS Users Community
|
- Path Traversal(CWE-22) [IPA Evaluation]
- Cross-Site Request Forgery(CWE-352) [IPA Evaluation]
- Cross-site Scripting(CWE-79) [IPA Evaluation]
- No Mapping(CWE-Other) [IPA Evaluation]
|
- CVE-2023-29009
- CVE-2023-43647
- CVE-2023-43648
- CVE-2023-43649
- CVE-2023-43792
|
- JVN : JVN#45547161
- National Vulnerability Database (NVD) : CVE-2023-29009
- National Vulnerability Database (NVD) : CVE-2023-43647
- National Vulnerability Database (NVD) : CVE-2023-43648
- National Vulnerability Database (NVD) : CVE-2023-43649
- National Vulnerability Database (NVD) : CVE-2023-43792
|
- [2023/10/27]
Web page was published
- [2024/05/07]
References : Contents were added
|