First published: Mon Mar 28 2022(Updated: )
74cmsSE v3.4.1 was discovered to contain an arbitrary file read vulnerability via the $url parameter at \index\controller\Download.php.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Ditcms | =3.4.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2022-26271 is classified as a medium severity vulnerability due to its potential for arbitrary file reading, which can lead to information disclosure.
To fix CVE-2022-26271, upgrade 74cmsSE to a version higher than 3.4.1 or implement input validation to sanitize the $url parameter.
CVE-2022-26271 affects version 3.4.1 of 74cmsSE.
CVE-2022-26271 is an arbitrary file read vulnerability, allowing attackers to read sensitive files on the server.
CVE-2022-26271 was discovered in the 74cmsSE version 3.4.1 software.