CVE-2023-1682: Xunrui CMS Install.txt direct request
Published Mar 28, 2023
·Updated
A vulnerability has been found in Xunrui CMS 4.61 and classified as problematic. Affected by this vulnerability is an unknown functionality of the file /dayrui/My/Config/Install.txt. The manipulation leads to direct request. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-224239.
Affected Software
1 affected component
XunRuiCMS XunRuiCMS=4.6.1
Event History
Mar 28, 2023
CVE Published
11:31 PM
Data Sourced
11:31 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2023-1682?
The severity of CVE-2023-1682 is high (7.5).
2
What is the affected software of CVE-2023-1682?
The affected software of CVE-2023-1682 is Xunrui CMS 4.61.
3
How does CVE-2023-1682 affect Xunrui CMS 4.61?
CVE-2023-1682 allows for direct request manipulation in Xunrui CMS 4.61.
4
Is CVE-2023-1682 exploitable remotely?
Yes, CVE-2023-1682 can be exploited remotely.
5
How can I fix CVE-2023-1682 in Xunrui CMS 4.61?
To fix CVE-2023-1682 in Xunrui CMS 4.61, consider applying the available patches or updates provided by the vendor.