CVE-2023-47283: Path Traversal
Directory traversal vulnerability in CubeCart prior to 6.5.3 allows a remote authenticated attacker with an administrative privilege to obtain files in the system.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the vulnerability ID?
The vulnerability ID is CVE-2023-47283.
What is the title of the vulnerability?
The title of the vulnerability is 'Directory traversal vulnerability in CubeCart prior to 6.5.3 allows a remote authenticated attacker ...'
What is the description of the vulnerability?
The description of the vulnerability is 'Directory traversal vulnerability in CubeCart prior to 6.5.3 allows a remote authenticated attacker with an administrative privilege to obtain files in the system.'
What software versions are affected by the vulnerability?
The vulnerability affects CubeCart versions up to and including 6.5.3.
What is the severity of the vulnerability?
The severity of the vulnerability is medium, with a CVSS score of 4.9.
What is the Common Weakness Enumeration (CWE) ID for the vulnerability?
The Common Weakness Enumeration (CWE) ID for the vulnerability is CWE-22.
How can an attacker exploit this vulnerability?
An attacker with administrative privilege can exploit this vulnerability by performing directory traversal attacks to access files on the system.
Is there a security update available for this vulnerability?
Yes, a security update (CubeCart 6.5.3) has been released to address this vulnerability.
Where can I find more information about this vulnerability?
You can find more information about this vulnerability in the CubeCart forums and the Japan Vulnerability Notes (JVN) website.