CVE-2022-37191: Medium severity tina tinacms vulnerability
The component "cuppa/api/index.php" of CuppaCMS v1.0 is Vulnerable to LFI. An authenticated user can read system files via crafted POST request using [function] parameter value as LFI payload.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2022-37191?
CVE-2022-37191 has a high severity due to its potential to allow authenticated users to read sensitive system files.
How do I fix CVE-2022-37191?
To fix CVE-2022-37191, you should update CuppaCMS to a version that contains the patch for Local File Inclusion vulnerabilities.
Who is affected by CVE-2022-37191?
Any user of CuppaCMS version 1.0 is affected by CVE-2022-37191 if they have authenticated access to the system.
What kind of attacks can CVE-2022-37191 facilitate?
CVE-2022-37191 can facilitate Local File Inclusion attacks, allowing attackers to view sensitive files on the server.
Is CVE-2022-37191 easily exploitable?
Yes, CVE-2022-37191 can be easily exploited by authenticated users through specially crafted POST requests.