CVE-2022-28118: Critical severity sscms Siteserver Cms vulnerability
Published May 3, 2022
·Updated
SiteServer CMS v7.x allows attackers to execute arbitrary code via a crafted plug-in.
Affected Software
1 affected component
sscms Siteserver Cms>=7.0.0<=7.1.2
Event History
May 3, 2022
CVE Published
via MITRE·12:08 AM
Data Sourced
via MITRE·12:08 AM
Description
Data Sourced
via NVD·01:15 AM
DescriptionSeverityAffected Software
Frequently Asked Questions
1
What is CVE-2022-28118?
CVE-2022-28118 is a vulnerability in SiteServer CMS v7.x that allows attackers to execute arbitrary code via a crafted plug-in.
2
How severe is CVE-2022-28118?
CVE-2022-28118 is classified as critical with a severity score of 9.8.
3
Which versions of SiteServer CMS are affected by CVE-2022-28118?
CVE-2022-28118 affects SiteServer CMS v7.x, specifically versions 7.0.0 through 7.1.2.
4
How can an attacker exploit CVE-2022-28118?
Attackers can exploit CVE-2022-28118 by using a crafted plug-in to execute arbitrary code.
5
Are there any references available for CVE-2022-28118?
Yes, you can find references for CVE-2022-28118 at the following links: [1] http://siteserver.com [2] https://github.com/Richard-Tang/SSCMS-PluginShell/blob/main/Detail.md [3] https://github.com/siteserver/cms