CVE-2024-41924 Vulnerability Details

  /     /     /  

CVE-2024-41924 Metadata Quick Info

CVE Published: 30/07/2024 | CVE Updated: 02/08/2024 | CVE Year: 2024
Source: jpcert | Vendor: EC-CUBE CO.,LTD. | Product: EC-CUBE 4 series
Status : PUBLISHED

CVE-2024-41924 Description

Acceptance of extraneous untrusted data with trusted data vulnerability exists in EC-CUBE 4 series. If this vulnerability is exploited, an attacker who obtained the administrative privilege may install an arbitrary PHP package. If the obsolete versions of PHP packages are installed, the product may be affected by some known vulnerabilities.

Metrics

CVSS Version: 3.1 | Base Score: n/a
Vector: n/a

l➤ Exploitability Metrics:
    Attack Vector (AV)*
    Attack Complexity (AC)*
    Privileges Required (PR)*
    User Interaction (UI)*
    Scope (S)*

l➤ Impact Metrics:
    Confidentiality Impact (C)*
    Integrity Impact (I)*
    Availability Impact (A)*

Weakness Enumeration (CWE)

CWE-ID:
CWE Name: Acceptance of extraneous untrusted data with trusted data
Source: EC-CUBE CO.,LTD.

Common Attack Pattern Enumeration and Classification (CAPEC)

CAPEC-ID:
CAPEC Description:


Source: NVD (National Vulnerability Database).