PT-2022-16540 · Elitecms · Elitecms
Published
2022-02-01
·
Updated
2022-02-05
·
CVE-2022-24218
CVSS v3.1
9.1
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
eliteCMS version 1.0
Description
An issue in the "/admin/delete image.php" endpoint of eliteCMS allows attackers to delete arbitrary files.
Recommendations
For eliteCMS version 1.0, consider restricting access to the "/admin/delete image.php" endpoint until a patch is available. As a temporary workaround, avoid using the delete functionality in this endpoint to minimize the risk of exploitation.
Exploit
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Elitecms