CVE-2022-27256: Medium severity hubzilla vulnerability
Published Apr 13, 2022
·Updated
A PHP Local File inclusion vulnerability in the Redbasic theme for Hubzilla before version 7.2 allows remote attackers to include arbitrary php files via the schema parameter.
Affected Software
1 affected component
Hubzilla Hubzilla<7.2
Remediation
Event History
Apr 13, 2022
CVE Published
via MITRE·01:35 PM
Data Sourced
via MITRE·01:35 PM
Description
Frequently Asked Questions
1
What is CVE-2022-27256?
CVE-2022-27256 refers to a PHP Local File inclusion vulnerability in the Redbasic theme for Hubzilla before version 7.2.
2
How does CVE-2022-27256 affect Hubzilla?
CVE-2022-27256 allows remote attackers to include arbitrary PHP files in Hubzilla before version 7.2.
3
What is the severity of CVE-2022-27256?
The severity of CVE-2022-27256 is medium, with a CVSS score of 6.1.
4
How can remote attackers exploit CVE-2022-27256?
Remote attackers can exploit CVE-2022-27256 by manipulating the schema parameter to include arbitrary PHP files.
5
Is there a fix available for CVE-2022-27256?
Yes, a fix for CVE-2022-27256 is available in version 7.2 of the Hubzilla software.