Published:2021/05/21 Last Updated:2021/05/21
JVN#53910556
Multiple cross-site scripting vulnerabilities in multiple PHP Factory products
Overview
Multiple products provided by PHP Factory contain multiple cross-site scripting vulnerabilities.
Products Affected
CVE-2021-20723
- [MailForm01] free edition versions which the last updated date listed at the top of descriptions in the program file is from December 12, 2014 to July 27, 2018.
- [Telop01] free edition ver1.0.1 and earlier
- [Calendar01] free edition ver1.0.1 and earlier
Description
Multiple products provided by PHP Factory contain multiple cross-site scripting vulnerabilities listed below.
- Reflected cross-site scripting vulnerability (CWE-79) - CVE-2021-20723
CVSS v3 CVSS:3.0/AV:N/AC:H/PR:N/UI:R/S:C/C:L/I:L/A:N Base Score: 4.7 CVSS v2 AV:N/AC:H/Au:N/C:N/I:P/A:N Base Score: 2.6 - Reflected cross-site scripting vulnerability in the admin page (CWE-79) - CVE-2021-20724
CVSS v3 CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N Base Score: 6.1 CVSS v2 AV:N/AC:H/Au:N/C:N/I:P/A:N Base Score: 2.6 - Reflected cross-site scripting vulnerability in the admin page (CWE-79) - CVE-2021-20725
CVSS v3 CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N Base Score: 6.1 CVSS v2 AV:N/AC:H/Au:N/C:N/I:P/A:N Base Score: 2.6
Impact
- An arbitrary script may be executed on the user's web browser - CVE-2021-20723
- An arbitrary script may be executed on the logged-in user's web browser - CVE-2021-20724, CVE-2021-20725
Solution
Update the software
Update to the latest version according to the information provided by the developer.
Add code to the affected file
In situations where updating the software is difficult, add code to the affected file according to the information provided by the developer.
Vendor Status
References
JPCERT/CC Addendum
Vulnerability Analysis by JPCERT/CC
Credit
apple502j reported these vulnerabilities to IPA.
JPCERT/CC coordinated with the developer under Information Security Early Warning Partnership.
Other Information
JPCERT Alert |
|
JPCERT Reports |
|
CERT Advisory |
|
CPNI Advisory |
|
TRnotes |
|
CVE |
CVE-2021-20723 |
CVE-2021-20724 |
|
CVE-2021-20725 |
|
JVN iPedia |
JVNDB-2021-000042 |