First published: Tue Aug 17 2021(Updated: )
A remote code execution (RCE) in e/install/index.php of EmpireCMS 7.5 allows attackers to execute arbitrary PHP code via writing malicious code to the install file.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Phome Empirecms | =7.5 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2020-22937 is rated as critical with a CVSS score of 9.8.
Attackers can exploit CVE-2020-22937 by executing arbitrary PHP code through writing malicious code to the install file in e/install/index.php of EmpireCMS 7.5.
To fix CVE-2020-22937, it is recommended to apply the latest security patches provided by the software vendor.