ZeroHour

CVE-2022-27061

PoC ×3
CVSS 3.1
7.2 high
EPSS
3%p85
Published
()
Modified
Description

AeroCMS v0.0.1 was discovered to contain an arbitrary file upload vulnerability via the Post Image function under the Admin panel. This vulnerability allows attackers to execute arbitrary code via a crafted PHP file.

Vendors
aerocms project
Products
aerocms
Weakness
CWE-434
Vector
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.