PT-2022-24848 · Orckestra · Orckestra C1 Cms

Markus Wulftange

·

Published

2022-09-27

·

Updated

2022-09-30

·

CVE-2022-39256

CVSS v3.1

9.0

Critical

VectorAV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Orckestra C1 CMS versions prior to 6.13
Description A vulnerability in Orckestra C1 CMS allows remote attackers to execute arbitrary code on affected installations. Authentication is required to exploit this issue. The authenticated user may perform the actions unknowingly by visiting a specially crafted site.
Recommendations For versions prior to 6.13, upgrade to C1 CMS v6.13 or newer to resolve the issue. As a temporary workaround, consider restricting access to the system to minimize the risk of exploitation until the upgrade can be applied.

Exploit

Fix

Deserialization of Untrusted Data

Weakness Enumeration

Related Identifiers

CVE-2022-39256
GHSA-GFHP-JGP6-838J

Affected Products

Orckestra C1 Cms