CVE-2022-36215: High severity dedecms v6 vulnerability
Published Aug 17, 2022
·Updated
DedeBIZ v6 was discovered to contain a remote code execution vulnerability in sysinfo.php.
Affected Software
1 affected component
DedeBIZ Dedecmsv6=6.0.0
Event History
Aug 17, 2022
CVE Published
via MITRE·07:12 PM
Data Sourced
via MITRE·07:12 PM
Description
Frequently Asked Questions
1
What is CVE-2022-36215?
CVE-2022-36215 is a remote code execution vulnerability found in DedeBIZ v6 in the sys_info.php file.
2
How severe is CVE-2022-36215?
CVE-2022-36215 has a severity rating of 7.2, which is considered high.
3
What software version is affected by CVE-2022-36215?
CVE-2022-36215 affects DedeBIZ v6.0.0.
4
What is the vulnerability in CVE-2022-36215?
CVE-2022-36215 is a remote code execution vulnerability in the sys_info.php file of DedeBIZ v6.
5
Is there a proof of concept available for CVE-2022-36215?
Yes, a proof of concept for CVE-2022-36215 is available at the following link: [https://github.com/whitehatl/Vulnerability/blob/main/web/dedebiz/6.0.0/sys_info.poc.md](https://github.com/whitehatl/Vulnerability/blob/main/web/dedebiz/6.0.0/sys_info.poc.md)