CVE-2022-35239: Input Validation
The image file management page of SolarView Compact SV-CPT-MC310 Ver.7.23 and earlier, and SV-CPT-MC310F Ver.7.23 and earlier contains an insufficient verification vulnerability when uploading files. If this vulnerability is exploited, arbitrary PHP code may be executed if a remote authenticated attacker uploads a specially crafted PHP file.
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability ID?
The vulnerability ID is CVE-2022-35239.
What is the severity of CVE-2022-35239?
The severity of CVE-2022-35239 is high (8.8).
What is the affected software?
The affected software is SolarView Compact SV-CPT-MC310 Ver.7.23 and earlier, and SV-CPT-MC310F Ver.7.23 and earlier.
What is the vulnerability in the affected software?
The vulnerability in the affected software is an insufficient verification vulnerability when uploading files, which may allow execution of arbitrary PHP code.
How can I fix CVE-2022-35239?
Refer to the official references provided for mitigation steps and firmware updates.