CVE-2022-37190: High severity tina tinacms vulnerability
CuppaCMS 1.0 is vulnerable to Remote Code Execution (RCE). An authenticated user can control both parameters (action and function) from "/api/index.php.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2022-37190?
CVE-2022-37190 is classified as a critical vulnerability due to its potential for Remote Code Execution (RCE).
How do I fix CVE-2022-37190?
To fix CVE-2022-37190, upgrade to a patched version of CuppaCMS that addresses this RCE vulnerability and ensures proper input validation.
Who is affected by CVE-2022-37190?
CVE-2022-37190 affects users of CuppaCMS version 1.0, specifically authenticated users with access to the API.
What are the risks associated with CVE-2022-37190?
The risks include unauthorized remote code execution, which could allow attackers to gain control of the server and compromise sensitive data.
Is authentication required to exploit CVE-2022-37190?
Yes, exploitation of CVE-2022-37190 requires an authenticated user to manipulate parameters in the CuppaCMS API.