PT-2022-17321 · Cuppacms · Cuppacms

Bkfish

·

Published

2022-03-15

·

Updated

2022-10-27

·

CVE-2022-25486

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions CuppaCMS version 1.0
Description The issue is related to a local file inclusion via the url parameter in the /alerts/alertConfigField.php endpoint. This allows for potential unauthorized access to local files.
Recommendations For CuppaCMS version 1.0, consider restricting access to the /alerts/alertConfigField.php endpoint until a patch is available. As a temporary workaround, avoid using the url parameter in this endpoint to minimize the risk of exploitation.

Exploit

Fix

Weakness Enumeration

Related Identifiers

CVE-2022-25486

Affected Products

Cuppacms