PT-2022-17331 · Unknown+1 · Jquery File Upload+1

Bkfish

·

Published

2022-03-15

·

Updated

2022-03-23

·

CVE-2022-25495

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions CuppaCMS version 1.0
Description The issue allows attackers to upload arbitrary files and execute arbitrary code via a crafted PHP file. This is possible due to a flaw in the /jquery file upload/server/php/index.php component.
Recommendations For CuppaCMS version 1.0, consider disabling the /jquery file upload/server/php/index.php component until a patch is available to prevent arbitrary file uploads and code execution. Restrict access to this component to minimize the risk of exploitation.

Exploit

Fix

Unrestricted File Upload

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2022-25495

Affected Products

Cuppacms
Jquery File Upload