PT-2024-19620 · Bosscms · Bosscms

N0Sleeper

·

Published

2024-01-30

·

Updated

2024-02-03

·

CVE-2024-22938

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions BossCMS version 1.3.0
Description The issue allows a local attacker to execute arbitrary code and escalate privileges. This is achieved via the init function in the admin.class.php component.
Recommendations For BossCMS version 1.3.0, consider restricting access to the admin.class.php component until a patch is available. As a temporary workaround, disabling the init function can help minimize the risk of exploitation.

Exploit

Fix

Incorrect Authorization

Weakness Enumeration

Related Identifiers

CVE-2024-22938

Affected Products

Bosscms