ZeroHour

CVE-2022-24262

PoC
CVSS 3.1
8.8 high
EPSS
2%p78
Published
()
Modified
Description

The config restore function of Voipmonitor GUI before v24.96 does not properly check files sent as restore archives, allowing remote attackers to execute arbitrary commands via a crafted file in the web root.

Vendors
voipmonitor
Products
voipmonitor
Weakness
CWE-434
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

In the news