PT-2022-20717 · Docebo · Docebo Community Edition

Published

2022-06-22

·

Updated

2024-08-03

·

CVE-2022-31362

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Docebo Community Edition versions 4.0.5 and below
Description The issue is related to an arbitrary file upload vulnerability. It is noted that this vulnerability only affects products that are no longer supported by the maintainer.
Recommendations For Docebo Community Edition versions 4.0.5 and below, as a temporary workaround, consider restricting access to file upload functionality until a solution is available. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Unrestricted File Upload

Weakness Enumeration

Related Identifiers

CVE-2022-31362

Affected Products

Docebo Community Edition