Published:2024/02/01  Last Updated:2024/02/01
      
        JVN#41129639
        Payment EX vulnerable to information disclosure
              
      
      Overview
Payment EX provided by Simplesite contains an information disclosure vulnerability.
Products Affected
- Payment EX Ver1.1.5b and earlier
 
Description
Payment EX provided by Simplesite contains an information disclosure vulnerability (CWE-200).
Impact
A remote unauthenticated attacker may obtain the information of the user who purchases merchandise using Payment EX.
Solution
Update the Software
Update the software to the latest version according to the information provided by the developer.
Vendor Status
| Vendor | Link | 
| Simplesite | Site exclusively for purchasers of PayPal payment series (Text in Japanese, login required) | 
References
JPCERT/CC Addendum
Vulnerability Analysis by JPCERT/CC
              CVSS v3
              CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
              
                
            
            
                  Base Score:
                  7.5
                
                
              | Attack Vector(AV) | Physical (P) | Local (L) | Adjacent (A) | Network (N) | 
|---|---|---|---|---|
| Attack Complexity(AC) | High (H) | Low (L) | ||
| Privileges Required(PR) | High (H) | Low (L) | None (N) | |
| User Interaction(UI) | Required (R) | None (N) | ||
| Scope(S) | Unchanged (U) | Changed (C) | ||
| Confidentiality Impact(C) | None (N) | Low (L) | High (H) | |
| Integrity Impact(I) | None (N) | Low (L) | High (H) | |
| Availability Impact(A) | None (N) | Low (L) | High (H) | 
                CVSS v2
                AV:N/AC:L/Au:N/C:P/I:N/A:N
                
                  
              
              
                    Base Score:
                    5.0
                  
                  
                | Access Vector(AV) | Local (L) | Adjacent Network (A) | Network (N) | 
|---|---|---|---|
| Access Complexity(AC) | High (H) | Medium (M) | Low (L) | 
| Authentication(Au) | Multiple (M) | Single (S) | None (N) | 
| Confidentiality Impact(C) | None (N) | Partial (P) | Complete (C) | 
| Integrity Impact(I) | None (N) | Partial (P) | Complete (C) | 
| Availability Impact(A) | None (N) | Partial (P) | Complete (C) | 
Credit
Other Information
| JPCERT Alert | 
                                     | 
              
| JPCERT Reports | 
                                     | 
              
| CERT Advisory | 
                                     | 
              
| CPNI Advisory | 
                                     | 
              
| TRnotes | 
                                     | 
              
| CVE | 
                                    CVE-2024-24548 | 
              
| JVN iPedia | 
                                    JVNDB-2024-000015 |