CVE-2022-42092: Malicious File Upload
Published Oct 7, 2022
·Updated
Backdrop CMS 1.22.0 has Unrestricted File Upload vulnerability via 'themes' that allows attackers to Remote Code Execution.
Affected Software
1 affected component
BackdropCMS Backdrop Cms=1.22.0
Event History
Oct 7, 2022
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·06:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is CVE-2022-42092?
CVE-2022-42092 is a vulnerability in Backdrop CMS 1.22.0 that allows attackers to execute remote code through unrestricted file upload in 'themes'.
2
How severe is CVE-2022-42092?
CVE-2022-42092 has a severity rating of 7.2 (high).
3
How does CVE-2022-42092 occur?
CVE-2022-42092 occurs due to an unrestricted file upload vulnerability in the 'themes' feature of Backdrop CMS 1.22.0.
4
What software version is affected by CVE-2022-42092?
Backdrop CMS 1.22.0 is affected by CVE-2022-42092.
5
Is there a fix for CVE-2022-42092?
Yes, updating to a version higher than 1.22.0 of Backdrop CMS resolves the CVE-2022-42092 vulnerability.