First published: Mon Sep 12 2022(Updated: )
Cuppa CMS v1.0 was discovered to contain an arbitrary file upload vulnerability via the File Manager.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Tina Tinacms | =1.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2022-38296 is considered a high severity vulnerability due to its potential for arbitrary file upload.
To fix CVE-2022-38296, update Cuppa CMS to the latest version that includes the security patch for the arbitrary file upload vulnerability.
CVE-2022-38296 allows attackers to upload arbitrary files, potentially leading to unauthorized access and remote code execution.
Cuppa CMS version 1.0 is not safe to use if it has not been updated to address CVE-2022-38296.
You can determine vulnerability by checking if your Cuppa CMS installation is still at version 1.0 without any security updates addressing CVE-2022-38296.