PT-2022-12609 · Taocms · Taocms

Bkfish

·

Published

2022-01-19

·

Updated

2022-01-25

·

CVE-2021-46204

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Taocms version 3.0.2
Description The issue concerns an arbitrary file read vulnerability that can be exploited via the path parameter. Additionally, there is a SQL injection vulnerability via the taocmsincludeModelArticle.php file.
Recommendations For Taocms version 3.0.2, consider restricting access to the path parameter to prevent arbitrary file read exploitation. As a temporary workaround, restrict access to the taocmsincludeModelArticle.php file to minimize the risk of SQL injection. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

SQL injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2021-46204

Affected Products

Taocms