CVE-2022-44036: Malicious File Upload
DISPUTED In b2evolution 7.2.5, if configured with adminscanmanipulatesensitivefiles, arbitrary file upload is allowed for admins, leading to command execution. NOTE: the vendor's position is that this is "very obviously a feature not an issue and if you don't like that feature it is very obvious how to disable it."
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2022-44036?
The severity of CVE-2022-44036 is currently under dispute as it is perceived by the vendor as a feature rather than an issue.
How do I fix CVE-2022-44036?
To mitigate CVE-2022-44036, consider disabling the 'admins_can_manipulate_sensitive_files' configuration setting.
What software is affected by CVE-2022-44036?
CVE-2022-44036 affects b2evolution version 7.2.5 specifically.
What type of vulnerability is CVE-2022-44036?
CVE-2022-44036 is classified as an arbitrary file upload vulnerability that could lead to command execution.
Who reported CVE-2022-44036?
CVE-2022-44036 was reported based on the functionalities present in b2evolution but is disputed by the vendor.