Skip to content

管理画面のMFAバイパスが可能な脆弱性

Moderate
dotani1111 published GHSA-7rhv-h82h-vpjh Mar 5, 2026

Package

EC-CUBE

Affected versions

>= 4.1.0, <= 4.3.1

Patched versions

None

Description

MFAバイパスが可能な脆弱性

EC-CUBEバージョン

バージョン: 4.1.0 ~ 4.3.1

脆弱性の概要

管理者のIDとパスワードが漏洩している場合、本来必要な2段階認証を回避して管理画面にログインできてしまう問題です。

深刻度と影響

CVSS3.1スコア:基本評価:6.2 / 現状評価:5.7 / 環境評価(緩和・対策後):0.0

攻撃者は管理者権限を持つアカウントの2FA設定を強制的に上書きできます。これにより、正規の管理者を締め出しつつ、攻撃者自身が管理画面へログインし、機密情報の閲覧やWebサイトの改ざんなどの不正操作を行うことが可能になります。

脆弱性の詳細な原因

システムの実装において、2FA設定画面(/admin/two_factor_auth/set)へのアクセス制御に不備があり。

  1. TwoFactorAuthListener.php
    2FA認証チェックを除外するルート設定に、設定画面(admin_two_factor_auth_set)が含まれている。
  2. TwoFactorAuthController.php
    既に2FA設定済みのユーザーであっても、2FA認証を通過せずに新しい鍵の再設定(上書き)を受け入れてしまう仕様になっている。

攻撃の成立条件と手順

前提条件:
管理ユーザーのIDとパスワードを知っていること。
そのユーザーで2FAが有効化されていること。

攻撃手順:

  1. IDとパスワードでログインを試行する。
  2. 2FAコード入力画面が表示されるが、入力を行わずに直接URLを書き換えて /admin/two_factor_auth/set へアクセスする。
  3. アクセスが拒否されないため、攻撃者は新しい2FA秘密鍵を発行し、保存(上書き)する。
  4. 以降、攻撃者が作成した新しい2FAコードを使ってログインが可能になる。

Severity

Moderate

CVSS overall score

This score calculates overall vulnerability severity from 0 to 10 and is based on the Common Vulnerability Scoring System (CVSS).
/ 10

CVSS v3 base metrics

Attack vector
Network
Attack complexity
Low
Privileges required
High
User interaction
None
Scope
Unchanged
Confidentiality
High
Integrity
High
Availability
Low

CVSS v3 base metrics

Attack vector: More severe the more the remote (logically and physically) an attacker can be in order to exploit the vulnerability.
Attack complexity: More severe for the least complex attacks.
Privileges required: More severe if no privileges are required.
User interaction: More severe when no user interaction is required.
Scope: More severe when a scope change occurs, e.g. one vulnerable component impacts resources in components beyond its security scope.
Confidentiality: More severe when loss of data confidentiality is highest, measuring the level of data access available to an unauthorized user.
Integrity: More severe when loss of data integrity is the highest, measuring the consequence of data modification possible by an unauthorized user.
Availability: More severe when the loss of impacted component availability is highest.
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:L

CVE ID

No known CVE

Weaknesses

No CWEs