CVE-2022-27333: High severity idccms vulnerability
Published Mar 21, 2022
·Updated
idcCMS v1.10 was discovered to contain an issue which allows attackers to arbitrarily delete the install.lock file, resulting in a reset of the CMS settings and data.
Affected Software
2 affected components
Idccms Project Idccms=1.10
idccms idccms=1.10
Event History
Mar 21, 2022
CVE Published
via MITRE·09:05 PM
Data Sourced
via MITRE·09:05 PM
Description
Data Sourced
via NVD·10:15 PM
DescriptionSeverityAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2022-27333?
CVE-2022-27333 has a medium severity level due to its potential impact on CMS settings and data.
2
How do I fix CVE-2022-27333?
To fix CVE-2022-27333, ensure that proper file permissions are set to prevent unauthorized access to the install.lock file.
3
What are the risks of CVE-2022-27333?
The risks of CVE-2022-27333 include the arbitrary deletion of site configuration and data loss.
4
Which version of idcCMS is affected by CVE-2022-27333?
CVE-2022-27333 affects idcCMS version 1.10.
5
Can CVE-2022-27333 be exploited remotely?
Yes, CVE-2022-27333 can be exploited remotely by attackers who can access the vulnerable server.