CVE-2022-2636: Code Injection in hestiacp/hestiacp
Improper Control of Generation of Code ('Code Injection') in GitHub repository hestiacp/hestiacp prior to 1.6.6.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is CVE-2022-2636?
CVE-2022-2636 is a vulnerability that allows code injection in the Hestiacp Control Panel prior to version 1.6.6.
How severe is CVE-2022-2636?
CVE-2022-2636 has a severity rating of 8.8, which is considered high.
Which software versions are affected by CVE-2022-2636?
Hestiacp Control Panel versions up to and excluding 1.6.6 are affected by CVE-2022-2636.
How can I fix the CVE-2022-2636 vulnerability?
To fix the CVE-2022-2636 vulnerability, upgrade the Hestiacp Control Panel to version 1.6.6 or higher.
Where can I find more information about CVE-2022-2636?
More information about CVE-2022-2636 can be found at the following references: - GitHub commit: [https://github.com/hestiacp/hestiacp/commit/b178b9719bb2c98cf8a6db70065086f596afad81](https://github.com/hestiacp/hestiacp/commit/b178b9719bb2c98cf8a6db70065086f596afad81) - Huntr.dev: [https://huntr.dev/bounties/357c0390-631c-4684-b6e1-a6d8b2453d66](https://huntr.dev/bounties/357c0390-631c-4684-b6e1-a6d8b2453d66)