CVE-2022-31374: Malicious File Upload
Published Jun 21, 2022
·Updated
An arbitrary file upload vulnerability /images/background/1.php in of SolarView Compact 6.0 allows attackers to execute arbitrary code via a crafted php file.
Affected Software
2 affected components
Contec Sv-cpt-mc310 Firmware=6.0
Contec Sv-cpt-mc310
Event History
Jun 21, 2022
CVE Published
via MITRE·01:00 PM
Data Sourced
via MITRE·01:00 PM
Description
Frequently Asked Questions
1
What is CVE-2022-31374?
CVE-2022-31374 is an arbitrary file upload vulnerability in SolarView Compact 6.0 that allows attackers to execute arbitrary code via a crafted PHP file.
2
How severe is CVE-2022-31374?
CVE-2022-31374 has a severity rating of 9.8 (Critical).
3
Which software versions are affected by CVE-2022-31374?
SolarView Compact 6.0 is affected by CVE-2022-31374.
4
How can an attacker exploit CVE-2022-31374?
An attacker can exploit CVE-2022-31374 by uploading a crafted PHP file to the /images/background/1.php path.
5
Is there a fix for CVE-2022-31374?
There is currently no known fix for CVE-2022-31374. It is recommended to update to a secure version or apply any patches or workarounds provided by the vendor.