« Volver al listado

CVE-2023-50297

Estado: ModificadaMedia (6.1)—

Open redirect vulnerability in PowerCMS (6 Series, 5 Series, and 4 Series) allows a remote unauthenticated attacker to redirect users to arbitrary web sites via a specially crafted URL. Note that all versions of PowerCMS 3 Series and earlier which are unsupported (End-of-Life, EOL) are also affected by this vulnerability.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2023-50297",
  "cveTags": [],
  "metrics": {
    "ssvcV203": [
      {
        "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
        "ssvcData": {
          "id": "CVE-2023-50297",
          "role": "CISA Coordinator",
          "options": [
            {
              "exploitation": "none"
            },
            {
              "automatable": "no"
            },
            {
              "technicalImpact": "partial"
            }
          ],
          "version": "2.0.3",
          "timestamp": "2024-01-11T18:54:45.569296Z"
        }
      }
    ],
    "cvssMetricV31": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "scope": "CHANGED",
          "version": "3.1",
          "baseScore": 6.1,
          "attackVector": "NETWORK",
          "baseSeverity": "MEDIUM",
          "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N",
          "integrityImpact": "LOW",
          "userInteraction": "REQUIRED",
          "attackComplexity": "LOW",
          "availabilityImpact": "NONE",
          "privilegesRequired": "NONE",
          "confidentialityImpact": "LOW"
        },
        "impactScore": 2.7,
        "exploitabilityScore": 2.8
      }
    ]
  },
  "affected": [
    {
      "source": "vultures@jpcert.or.jp",
      "affectedData": [
        {
          "vendor": "Alfasado Inc.",
          "product": "PowerCMS (PowerCMS 6 Series)",
          "versions": [
            {
              "status": "affected",
              "version": "6.31 and earlier"
            }
          ]
        },
        {
          "vendor": "Alfasado Inc.",
          "product": "PowerCMS (PowerCMS 5 Series)",
          "versions": [
            {
              "status": "affected",
              "version": "5.24 and earlier"
            }
          ]
        },
        {
          "vendor": "Alfasado Inc.",
          "product": "PowerCMS (PowerCMS 4 Series)",
          "versions": [
            {
              "status": "affected",
              "version": "4.54 and earlier"
            }
          ]
        }
      ]
    }
  ],
  "published": "2023-12-26T06:15:07.473",
  "references": [
    {
      "url": "https://jvn.jp/en/jp/JVN32646742/",
      "tags": [
        "Third Party Advisory"
      ],
      "source": "vultures@jpcert.or.jp"
    },
    {
      "url": "https://www.powercms.jp/news/release-powercms-202312.html",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "vultures@jpcert.or.jp"
    },
    {
      "url": "https://jvn.jp/en/jp/JVN32646742/",
      "tags": [
        "Third Party Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://www.powercms.jp/news/release-powercms-202312.html",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Modified",
  "weaknesses": [
    {
      "type": "Primary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "CWE-601"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "Open redirect vulnerability in PowerCMS (6 Series, 5 Series, and 4 Series) allows a remote unauthenticated attacker to redirect users to arbitrary web sites via a specially crafted URL. Note that all versions of PowerCMS 3 Series and earlier which are unsupported (End-of-Life, EOL) are also affected by this vulnerability."
    },
    {
      "lang": "es",
      "value": "Vulnerabilidad de redireccionamiento abierto en PowerCMS (Series 6, 5 Series y 4 Series) permite que un atacante remoto no autenticado redirija a los usuarios a sitios web arbitrarios a través de una URL especialmente manipulada. Tenga en cuenta que todas las versiones de PowerCMS Serie 3 y anteriores que no son compatibles (End-of-Life, EOL) también se ven afectadas por esta vulnerabilidad."
    }
  ],
  "lastModified": "2026-06-17T06:39:26.783",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:alfasado:powercms:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "418BFF70-45BC-4F69-85DB-7C935B80CCEE",
              "versionEndExcluding": "4.55"
            },
            {
              "criteria": "cpe:2.3:a:alfasado:powercms:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "4394A42A-9BE5-4927-93D7-74D99542D7D1",
              "versionEndExcluding": "5.25",
              "versionStartIncluding": "5.0"
            },
            {
              "criteria": "cpe:2.3:a:alfasado:powercms:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "AEA525B4-37C1-4D8B-9755-740FD4665D0A",
              "versionEndIncluding": "6.31",
              "versionStartIncluding": "6.0"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "vultures@jpcert.or.jp"
}