PT-2021-10810 · Empirecms · Empirecms
Po1Ng
·
Published
2021-08-17
·
Updated
2022-10-26
·
CVE-2020-22937
CVSS v3.1
9.8
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
EmpireCMS version 7.5
Description
A remote code execution issue in the e/install/index.php file allows attackers to execute arbitrary PHP code by writing malicious code to the install file. This enables attackers to potentially gain control over the system.
Recommendations
For EmpireCMS version 7.5, consider removing or restricting access to the e/install/index.php file until a patch is available. As a temporary workaround, restrict write access to the install file to prevent malicious code from being written.
Exploit
Fix
RCE
Code Injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Empirecms