First published: Fri Nov 17 2023(Updated: )
Directory traversal vulnerability in CubeCart prior to 6.5.3 allows a remote authenticated attacker with an administrative privilege to obtain files in the system.
Credit: vultures@jpcert.or.jp
Affected Software | Affected Version | How to fix |
---|---|---|
Cubecart Cubecart | <6.5.3 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID is CVE-2023-47283.
The title of the vulnerability is 'Directory traversal vulnerability in CubeCart prior to 6.5.3 allows a remote authenticated attacker ...'
The description of the vulnerability is 'Directory traversal vulnerability in CubeCart prior to 6.5.3 allows a remote authenticated attacker with an administrative privilege to obtain files in the system.'
The vulnerability affects CubeCart versions up to and including 6.5.3.
The severity of the vulnerability is medium, with a CVSS score of 4.9.
The Common Weakness Enumeration (CWE) ID for the vulnerability is CWE-22.
An attacker with administrative privilege can exploit this vulnerability by performing directory traversal attacks to access files on the system.
Yes, a security update (CubeCart 6.5.3) has been released to address this vulnerability.
You can find more information about this vulnerability in the CubeCart forums and the Japan Vulnerability Notes (JVN) website.