CVE-2020-22937: Code Injection
Published Aug 17, 2021
·Updated
A remote code execution (RCE) in e/install/index.php of EmpireCMS 7.5 allows attackers to execute arbitrary PHP code via writing malicious code to the install file.
Affected Software
1 affected component
Phome Empirecms=7.5
Event History
Aug 17, 2021
CVE Published
via MITRE·06:52 PM
Data Sourced
via MITRE·06:52 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2020-22937?
The severity of CVE-2020-22937 is rated as critical with a CVSS score of 9.8.
2
How can I exploit CVE-2020-22937?
Attackers can exploit CVE-2020-22937 by executing arbitrary PHP code through writing malicious code to the install file in e/install/index.php of EmpireCMS 7.5.
3
Is there a fix available for CVE-2020-22937?
To fix CVE-2020-22937, it is recommended to apply the latest security patches provided by the software vendor.