CVE-2022-36226: High severity siteserver cms vulnerability
Published Aug 25, 2022
·Updated
SiteServerCMS 5.X has a Remote-download-Getshell-vulnerability via /SiteServer/Ajax/ajaxOtherService.aspx.
Affected Software
1 affected component
Siteservercms Project Siteservercms<=5.0.0
Event History
Aug 25, 2022
CVE Published
via MITRE·11:37 PM
Data Sourced
via MITRE·11:37 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2022-36226?
CVE-2022-36226 is considered a critical vulnerability due to its potential to allow remote code execution on affected systems.
2
How do I fix CVE-2022-36226?
To fix CVE-2022-36226, you should upgrade SiteServerCMS to the latest version beyond 5.0.0.
3
What are the risks associated with CVE-2022-36226?
The risks associated with CVE-2022-36226 include unauthorized access to the system and the potential for data compromise.
4
Which versions of SiteServerCMS are affected by CVE-2022-36226?
CVE-2022-36226 affects all versions of SiteServerCMS 5.X up to and including 5.0.0.
5
Can CVE-2022-36226 be exploited remotely?
Yes, CVE-2022-36226 can be exploited remotely via the vulnerable endpoint in SiteServerCMS.