Published:2020/11/06  Last Updated:2020/11/06

JVNVU#92053563
Multiple vulnerabilities in XOOPS module "XooNIps"

Overview

XOOPS module "XooNIps" contains multiple vulnerabilities.

Products Affected

  • XooNIps 3.49 and earlier

Description

XOOPS module "XooNIps" contains multiple vulnerabilities listed below.

  • SQL injection (CWE-89) - CVE-2020-5659
    CVSS v3 CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L Base Score: 6.3
  • Reflected cross-site scripting (CWE-79) - CVE-2020-5662
    CVSS v3 CVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:U/C:L/I:L/A:N Base Score: 4.6
  • Stored cross-site scripting (CWE-79) - CVE-2020-5663
    CVSS v3 CVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:U/C:L/I:L/A:N Base Score: 4.6
  • Deserialization of untrusted data (CWE-502) - CVE-2020-5664
    CVSS v3 CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H Base Score: 8.1

Impact

  • A logged in user may obtain and/or modify information in the database - CVE-2020-5659
  • An arbitrary script may be executed on the user's web browser - CVE-2020-5662, CVE-2020-5663
  • Arbitrary code may be executed if untrusted data is deserialized - CVE-2020-5664

Solution

Update the software
Update the software to the latest version according to the information provided by the developer.

Vendor Status

Vendor Link
Neuroinformatics Unit, Integrative Computational Brain Science Collaboration Division, RIKEN Center for Brain Science XooNIps Official Site
XooNIps 3.50 has been released

References

JPCERT/CC Addendum

Vulnerability Analysis by JPCERT/CC

Credit

stypr of Flatt Security Inc. reported this vulnerability to the developer and coordinated on his own.
After coordination was completed, this case was reported to JPCERT/CC, and JPCERT/CC coordinated with the developer for the publication.

Other Information

JPCERT Alert
JPCERT Reports
CERT Advisory
CPNI Advisory
TRnotes
CVE CVE-2020-5659
CVE-2020-5662
CVE-2020-5663
CVE-2020-5664
JVN iPedia