CVE-2022-29784: Medium severity sanluan publiccms vulnerability
Published Jun 3, 2022
·Updated
PublicCMS V4.0.202204.a and below contains an information leak via the component /views/directive/sys/SysConfigDataDirective.java.
Affected Software
1 affected component
PublicCMS publiccms<=4.0.202204.a
Remediation
Event History
Jun 3, 2022
CVE Published
via MITRE·08:27 PM
Data Sourced
via MITRE·08:27 PM
Description
Frequently Asked Questions
1
What is CVE-2022-29784?
CVE-2022-29784 is a vulnerability in PublicCMS V4.0.202204.a and below that allows for an information leak through the /views/directive/sys/SysConfigDataDirective.java component.
2
Is PublicCMS V4.0.202204.a affected by CVE-2022-29784?
Yes, PublicCMS V4.0.202204.a is affected by CVE-2022-29784.
3
What is the severity of CVE-2022-29784?
CVE-2022-29784 has a severity rating of 5.3 (medium).
4
How can the information leak in CVE-2022-29784 be exploited?
The information leak in CVE-2022-29784 can be exploited by using the /views/directive/sys/SysConfigDataDirective.java component.
5
How can I fix CVE-2022-29784?
To fix CVE-2022-29784, you should update PublicCMS to a version that is not affected by the vulnerability.