CVE-2022-23329: Malicious File Upload
Published Feb 4, 2022
·Updated
A vulnerability in ${"freemarker.template.utility.Execute"?new() of UJCMS Jspxcms v10.2.0 allows attackers to execute arbitrary commands via uploading malicious files.
Affected Software
1 affected component
Ujcms Jspxcms=10.2.0
Event History
Feb 4, 2022
CVE Published
via MITRE·09:03 PM
Data Sourced
via MITRE·09:03 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2022-23329?
CVE-2022-23329 has a severity rating of high due to its potential for arbitrary command execution.
2
How do I fix CVE-2022-23329?
To fix CVE-2022-23329, upgrade to a patched version of UJCMS Jspxcms beyond v10.2.0.
3
What kind of attacks can CVE-2022-23329 facilitate?
CVE-2022-23329 can facilitate attacks that allow an attacker to execute arbitrary commands on the server.
4
Which versions of UJCMS Jspxcms are affected by CVE-2022-23329?
CVE-2022-23329 affects UJCMS Jspxcms version 10.2.0.
5
How does CVE-2022-23329 allow attackers to upload malicious files?
CVE-2022-23329 exploits a vulnerability in file handling that permits attackers to upload files that can execute malicious commands.