PT-2022-17757 · 74Cmsse · 74Cmsse

N1Ce759

·

Published

2022-03-28

·

Updated

2022-03-31

·

CVE-2022-26271

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions 74cmsSE version 3.4.1
Description The issue allows for an arbitrary file read via the url parameter at the indexcontrollerDownload.php endpoint.
Recommendations For 74cmsSE version 3.4.1, avoid using the url parameter in the indexcontrollerDownload.php endpoint until the issue is resolved. Consider restricting access to the Download.php file to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this issue.

Exploit

Fix

Files Accessible to External Parties

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2022-26271

Affected Products

74Cmsse