CVE-2022-28053: Malicious File Upload
Published Apr 25, 2022
·Updated
Typemill v1.5.3 was discovered to contain an arbitrary file upload vulnerability via the upload function. This vulnerability allows attackers to execute arbitrary code via a crafted PHP file.
Affected Software
1 affected component
Typemill Typemill=1.5.3
Event History
Apr 25, 2022
CVE Published
via MITRE·12:43 PM
Data Sourced
via MITRE·12:43 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2022-28053?
CVE-2022-28053 is considered a critical vulnerability due to its potential for allowing arbitrary code execution.
2
How do I fix CVE-2022-28053?
To fix CVE-2022-28053, update Typemill to the latest version that has patched this vulnerability.
3
What type of vulnerability is CVE-2022-28053?
CVE-2022-28053 is an arbitrary file upload vulnerability that affects Typemill v1.5.3.
4
Who is affected by CVE-2022-28053?
Any user or organization using Typemill version 1.5.3 is affected by CVE-2022-28053.
5
Can CVE-2022-28053 be exploited remotely?
Yes, CVE-2022-28053 can be exploited remotely by an attacker to execute arbitrary code.