First published: Thu Mar 23 2023(Updated: )
XunRuiCMS v4.3.3 to v4.5.1 vulnerable to PHP file write and CMS PHP file inclusion, allows attackers to execute arbitrary php code, via the add function in cron.php.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Xunruicms | >=4.3.3<=4.5.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2022-30037 is a vulnerability in XunRuiCMS, versions 4.3.3 to 4.5.1, that allows attackers to execute arbitrary PHP code.
CVE-2022-30037 has a severity rating of 7.2, which is considered high.
CVE-2022-30037 affects XunRuiCMS versions 4.3.3 to 4.5.1, allowing attackers to execute arbitrary PHP code.
To fix CVE-2022-30037 in XunRuiCMS, you should update to a version higher than 4.5.1.
You can find more information about CVE-2022-30037 at the following link: https://weltolk.github.io/p/xunruicms-v4.3.3-to-v4.5.1-backstage-code-injection-vulnerabilityfile-write-and-file-inclusion/