PT-2022-24848 · Orckestra · Orckestra C1 Cms
Markus Wulftange
·
Published
2022-09-27
·
Updated
2022-09-30
·
CVE-2022-39256
CVSS v3.1
9.0
Critical
| Vector | AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Orckestra C1 CMS versions prior to 6.13
Description
A vulnerability in Orckestra C1 CMS allows remote attackers to execute arbitrary code on affected installations. Authentication is required to exploit this issue. The authenticated user may perform the actions unknowingly by visiting a specially crafted site.
Recommendations
For versions prior to 6.13, upgrade to C1 CMS v6.13 or newer to resolve the issue. As a temporary workaround, consider restricting access to the system to minimize the risk of exploitation until the upgrade can be applied.
Exploit
Fix
Deserialization of Untrusted Data
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Orckestra C1 Cms