SECURITY セキュリティ情報
2026/09/24 baserCMSプラグイン「アドオンマイグレーター」に任意のコード実行の脆弱性
baserCMSプラグイン「アドオンマイグレーター(BcAddonMigrator)」に任意のコード実行の脆弱性があります。
対象となる方は、早急に新バージョンへアップデートをお願いします。
対象
BcAddonMigrator 5.2.0 と、その前のバージョン
脆弱性
当該プラグインに管理者権限でログイン可能な攻撃者によって、細工されたプラグインまたはテーマの ZIP ファイルを変換させることで、サーバー上で任意の PHP コードを実行される可能性があります。第三者から受け取った ZIP ファイルを管理者が変換した場合も同様の影響を受けます。
1. アドオン変換処理における任意のコード実行(JVN#21754394)
本脆弱性は、管理画面を不特定多数のユーザーに利用させている場合、または信頼できない第三者から受け取ったプラグイン・テーマを変換する場合に対応が必要となる脆弱性です。
対策
BcAddonMigrator 5.2.1 以降にアップデートを行う。利用していないのであれば、プラグインの利用を停止する。
謝辞
- 野口晋義@三井物産セキュアディレクション株式会社
=========================================================================
The "Add-on Migrator" (BcAddonMigrator) plugin for baserCMS contains an arbitrary code execution vulnerability.
If you are affected by this issue, please update to the new version as soon as possible.
Target
BcAddonMigrator 5.2.0 and earlier versions
Vulnerability
An attacker logged in with administrator privileges could execute arbitrary PHP code on the server by having a crafted plugin or theme ZIP file converted. The same impact applies when an administrator converts a ZIP file received from a third party.
1. Arbitrary code execution during add-on conversion (JVN#21754394)
This vulnerability requires action if the admin panel is made available to an unspecified number of users, or if plugins or themes received from untrusted third parties are converted.
Countermeasures
Update BcAddonMigrator to version 5.2.1 or later, or disable the plugin if it is not in use.
Credits
- Kuniyoshi Noguchi@Mitsui Bussan Secure Directions, Inc.
