CVE-2022-4606: PHP Remote File Inclusion in flatpressblog/flatpress
Published Dec 18, 2022
·Updated
PHP Remote File Inclusion in GitHub repository flatpressblog/flatpress prior to 1.3.
Affected Software
1 affected component
flatpress flatpress<=1.2.1
Remediation
Event History
Dec 18, 2022
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·01:15 PM
RemedyDescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is CVE-2022-4606?
CVE-2022-4606 is a vulnerability in the GitHub repository flatpressblog/flatpress prior to version 1.3.
2
What is the severity of CVE-2022-4606?
CVE-2022-4606 has a severity rating of 9.8 (critical).
3
What software is affected by CVE-2022-4606?
Flatpress version 1.2.1 and prior versions are affected by CVE-2022-4606.
4
How can I fix CVE-2022-4606?
To fix CVE-2022-4606, upgrade Flatpress to version 1.3 or later.
5
Where can I find more information about CVE-2022-4606?
More information about CVE-2022-4606 can be found at the following references: [GitHub Commit](https://github.com/flatpressblog/flatpress/commit/c30d52b28483e1e512d0d81758d4c149f02b4068), [Huntr Report](https://huntr.dev/bounties/3dab0466-c35d-4163-b3c7-a8666e2f7d95).