First published: Tue Mar 15 2022(Updated: )
CuppaCMS v1.0 was discovered to contain a local file inclusion via the url parameter in /alerts/alertLightbox.php.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Tina Tinacms | =1.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2022-25485 has been assessed to have a medium severity due to its potential for local file inclusion, which could lead to sensitive information disclosure.
CVE-2022-25485 affects CuppaCMS version 1.0.
To mitigate CVE-2022-25485, upgrade to an updated version of CuppaCMS that addresses local file inclusion vulnerabilities.
CVE-2022-25485 is a local file inclusion vulnerability, primarily exploitable within the same server environment.
Local file inclusion in CVE-2022-25485 allows an attacker to include files on a server through the url parameter, potentially exposing sensitive data.