CVE-2026-4222: SSCMS download PathUtils.RemoveParentPath path traversal
A vulnerability was determined in SSCMS up to 7.4.0. This vulnerability affects the function PathUtils.RemoveParentPath of the file /api/admin/plugins/install/actions/download. This manipulation of the argument path causes path traversal. Remote exploitation of the attack is possible. The exploit has been publicly disclosed and may be utilized. The vendor was contacted early about this disclosure but did not respond in any way.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-4222?
CVE-2026-4222 has a medium severity rating due to the potential for unauthorized file access through path traversal.
How do I fix CVE-2026-4222?
To fix CVE-2026-4222, update SSCMS to version 7.4.1 or later where the vulnerability has been addressed.
What impact does CVE-2026-4222 have on SSCMS?
CVE-2026-4222 allows attackers to exploit path traversal vulnerabilities, leading to unauthorized file system access on affected SSCMS versions.
Which SSCMS versions are affected by CVE-2026-4222?
CVE-2026-4222 affects SSCMS versions up to and including 7.4.0.
Can CVE-2026-4222 be exploited remotely?
Yes, CVE-2026-4222 can be exploited remotely if an attacker sends a specially crafted request to the affected SSCMS endpoint.