PT-2021-10810 · Empirecms · Empirecms

Po1Ng

·

Published

2021-08-17

·

Updated

2022-10-26

·

CVE-2020-22937

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions EmpireCMS version 7.5
Description A remote code execution issue in the e/install/index.php file allows attackers to execute arbitrary PHP code by writing malicious code to the install file. This enables attackers to potentially gain control over the system.
Recommendations For EmpireCMS version 7.5, consider removing or restricting access to the e/install/index.php file until a patch is available. As a temporary workaround, restrict write access to the install file to prevent malicious code from being written.

Exploit

Fix

RCE

Code Injection

Weakness Enumeration

Related Identifiers

CVE-2020-22937

Affected Products

Empirecms