PT-2022-11901 · Unknown · Cmswing Cms
Jason1314Zhang
·
Published
2022-03-23
·
Updated
2022-03-29
·
CVE-2021-43736
CVSS v3.1
9.8
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
CmsWing CMS version 1.3.7
Description
The issue is related to a Remote Code Execution (RCE) vulnerability. It can be exploited via the
log rule parameter.Recommendations
For CmsWing CMS version 1.3.7, avoid using the
log rule parameter until a fix is available. As a temporary workaround, consider restricting access to the parameter to minimize the risk of exploitation.Exploit
Fix
Argument Injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Cmswing Cms