CVE-2022-30037: High severity xunruicms vulnerability
Published Mar 23, 2023
·Updated
XunRuiCMS v4.3.3 to v4.5.1 vulnerable to PHP file write and CMS PHP file inclusion, allows attackers to execute arbitrary php code, via the add function in cron.php.
Affected Software
1 affected component
XunRuiCMS XunRuiCMS>=4.3.3<=4.5.1
Event History
Mar 23, 2023
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Frequently Asked Questions
1
What is CVE-2022-30037?
CVE-2022-30037 is a vulnerability in XunRuiCMS, versions 4.3.3 to 4.5.1, that allows attackers to execute arbitrary PHP code.
2
How severe is CVE-2022-30037?
CVE-2022-30037 has a severity rating of 7.2, which is considered high.
3
How does CVE-2022-30037 affect XunRuiCMS?
CVE-2022-30037 affects XunRuiCMS versions 4.3.3 to 4.5.1, allowing attackers to execute arbitrary PHP code.
4
How can I fix CVE-2022-30037 in XunRuiCMS?
To fix CVE-2022-30037 in XunRuiCMS, you should update to a version higher than 4.5.1.
5
Where can I find more information about CVE-2022-30037?
You can find more information about CVE-2022-30037 at the following link: https://weltolk.github.io/p/xunruicms-v4.3.3-to-v4.5.1-backstage-code-injection-vulnerabilityfile-write-and-file-inclusion/