Published:2021/05/21  Last Updated:2021/05/21

JVN#53910556
Multiple cross-site scripting vulnerabilities in multiple PHP Factory products

Overview

Multiple products provided by PHP Factory contain multiple cross-site scripting vulnerabilities.

Products Affected

CVE-2021-20723

  • [MailForm01] free edition versions which the last updated date listed at the top of descriptions in the program file is from December 12, 2014 to July 27, 2018.
CVE-2021-20724
  • [Telop01] free edition ver1.0.1 and earlier
CVE-2021-20725
  • [Calendar01] free edition ver1.0.1 and earlier

Description

Multiple products provided by PHP Factory contain multiple cross-site scripting vulnerabilities listed below.

  • Reflected cross-site scripting vulnerability (CWE-79) - CVE-2021-20723
    CVSS v3 CVSS:3.0/AV:N/AC:H/PR:N/UI:R/S:C/C:L/I:L/A:N Base Score: 4.7
    CVSS v2 AV:N/AC:H/Au:N/C:N/I:P/A:N Base Score: 2.6
  • Reflected cross-site scripting vulnerability in the admin page (CWE-79) - CVE-2021-20724
    CVSS v3 CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N Base Score: 6.1
    CVSS v2 AV:N/AC:H/Au:N/C:N/I:P/A:N Base Score: 2.6
  • Reflected cross-site scripting vulnerability in the admin page (CWE-79) - CVE-2021-20725
    CVSS v3 CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N Base Score: 6.1
    CVSS v2 AV:N/AC:H/Au:N/C:N/I:P/A:N Base Score: 2.6

Impact

  • An arbitrary script may be executed on the user's web browser - CVE-2021-20723
  • An arbitrary script may be executed on the logged-in user's web browser - CVE-2021-20724, CVE-2021-20725

Solution

Update the software
Update to the latest version according to the information provided by the developer.

Add code to the affected file
In situations where updating the software is difficult, add code to the affected file according to the information provided by the developer.

References

JPCERT/CC Addendum

Vulnerability Analysis by JPCERT/CC

Credit

apple502j reported these vulnerabilities to IPA.
JPCERT/CC coordinated with the developer under Information Security Early Warning Partnership.

Other Information

JPCERT Alert
JPCERT Reports
CERT Advisory
CPNI Advisory
TRnotes
CVE CVE-2021-20723
CVE-2021-20724
CVE-2021-20725
JVN iPedia JVNDB-2021-000042