[Japanese]
|
JVNDB-2023-000118
|
Multiple vulnerabilities in CubeCart
|
CubeCart provided by CubeCart Limited contains multiple vulnerabilities listed below.
- Cross-site request forgery (CWE-352) - CVE-2023-38130
- Directory traversal (CWE-22) - CVE-2023-42428
- Directory traversal (CWE-22) - CVE-2023-47283
- OS command injection (CWE-78) - CVE-2023-47675
Gen Sato of Mitsui Bussan Secure Directions, Inc. reported these vulnerabilities to the developer first, and to IPA later.
JPCERT/CC coordinated with the developer under Information Security Early Warning Partnership.
|
CVSS V3 Severity: Base Metrics 9.1 (Critical) [IPA Score]
- Attack Vector: Network
- Attack Complexity: Low
- Privileges Required: High
- User Interaction: None
- Scope: Changed
- Confidentiality Impact: High
- Integrity Impact: High
- Availability Impact: High
CVSS V2 Severity: Base Metrics 6.5 (Medium) [IPA Score]
- Access Vector: Network
- Access Complexity: Low
- Authentication: Single Instance
- Confidentiality Impact: Partial
- Integrity Impact: Partial
- Availability Impact: Partial
The above CVSS base scores have been assigned for CVE-2023-47675
|
CVSS V3 Severity:
Base Metrics
4.3 (Medium) [IPA Score]
-
Attack Vector: Network
-
Attack Complexity: Low
-
Privileges Required: None
-
User Interaction: Required
-
Scope: Unchanged
-
Confidentiality Impact: None
-
Integrity Impact: Low
-
Availability Impact: None
CVSS V2 Severity:Base Metrics
2.6 (Low)
[IPA Score]
-
Access Vector: Network
-
Access Complexity: High
-
Authentication: None
-
Confidentiality Impact: None
-
Integrity Impact: Partial
-
Availability Impact: None
The above CVSS base scores have been assigned for CVE-2023-38130
|
CVSS V3 Severity:
Base Metrics
2.7 (Low) [IPA Score]
-
Attack Vector: Network
-
Attack Complexity: Low
-
Privileges Required: High
-
User Interaction: None
-
Scope: Unchanged
-
Confidentiality Impact: None
-
Integrity Impact: Low
-
Availability Impact: None
CVSS V2 Severity:Base Metrics
4.0 (Medium)
[IPA Score]
-
Access Vector: Network
-
Access Complexity: Low
-
Authentication: Single
-
Confidentiality Impact: None
-
Integrity Impact: Partial
-
Availability Impact: None
The above CVSS base scores have been assigned for CVE-2023-42428
|
CVSS V3 Severity:
Base Metrics
2.7 (Low) [IPA Score]
-
Attack Vector: Network
-
Attack Complexity: Low
-
Privileges Required: High
-
User Interaction: None
-
Scope: Unchanged
-
Confidentiality Impact: Low
-
Integrity Impact: None
-
Availability Impact: None
CVSS V2 Severity:Base Metrics
4.0 (Medium)
[IPA Score]
-
Access Vector: Network
-
Access Complexity: Low
-
Authentication: Single
-
Confidentiality Impact: Partial
-
Integrity Impact: None
-
Availability Impact: None
The above CVSS base scores have been assigned for CVE-2023-47283
|
|
CubeCart Limited
- CubeCart versions prior to 6.5.3
|
|
- A remote attacker may delete data in the system - CVE-2023-38130
- A user with an administrative privilege may delete directories and files in the system - CVE-2023-42428
- A user with an administrative privilege may obtain files in the system - CVE-2023-47283
- A user with an administrative privilege may execute an arbitrary OS command - CVE-2023-47675
|
CVE-2023-38130, CVE-2023-42428, CVE-2023-47283
[Update the software]
Update the software to the latest version according to the information provided by the developer.
The developer addressed the vulnerabilities in the following versions:
CVE-2023-47675
[Apply the Workaround]
No fix is available for this vulnerability. The developer recommends disabling the dangerous PHP functions.
The following is the developer's suggestion to add to php.ini.
disable_functions = exec, system, passthru, pcntl_exec, popen, proc_open, shell_exec
For more information, refer to the information provided by the developer.
|
CubeCart Limited
|
- Path Traversal(CWE-22) [IPA Evaluation]
- Cross-Site Request Forgery(CWE-352) [IPA Evaluation]
- OS Command Injection(CWE-78) [IPA Evaluation]
|
- CVE-2023-38130
- CVE-2023-42428
- CVE-2023-47283
- CVE-2023-47675
|
- JVN : JVN#22220399
- National Vulnerability Database (NVD) : CVE-2023-38130
- National Vulnerability Database (NVD) : CVE-2023-42428
- National Vulnerability Database (NVD) : CVE-2023-47283
- National Vulnerability Database (NVD) : CVE-2023-47675
|
- [2023/11/17]
Web page was published
- [2024/04/30]
References : Contents were added
|