ZeroHour

CVE-2022-30007

PoC
CVSS 3.1
7.2 high
EPSS
<1%p60
Published
()
Modified
Description

GXCMS V1.5 has a file upload vulnerability in the background. The vulnerability is the template management page. You can edit any template content and then rename to PHP suffix file, after calling PHP file can control the server.

Vendors
gxcms project
Products
gxcms
Weakness
CWE-434
Vector
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.