Unknown · Tosei Online Store Management System · CVE-2024-7897
**Name of the Vulnerable Software and Affected Versions**
Tosei Online Store Management System versions 4.02 through 4.04
**Description**
A critical issue has been discovered, affecting an unknown part of the file /cgi-bin/tosei kikai.php. The manipulation of the `kikaibangou` argument leads to command injection, allowing for remote attacks. The exploit has been publicly disclosed, and the vendor was contacted but did not respond.
**Recommendations**
For versions 4.02 through 4.04, as a temporary workaround, consider restricting access to the /cgi-bin/tosei kikai.php file until a patch is available. Avoid using the `kikaibangou` argument in the affected file to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this issue.