SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2022-24247

RiteCMS version 3.1.0 and below suffers from an arbitrary file overwrite via path traversal vulnerability in Admin Panel.

MEDIUM 6.5EPSS 4.15%

Does this matter?

Lower severity and a low EPSS score (4.15%). Track it; it rarely justifies an emergency change on its own.

Description

RiteCMS version 3.1.0 and below suffers from an arbitrary file overwrite via path traversal vulnerability in Admin Panel. Exploiting the vulnerability allows an authenticated attacker to overwrite any file in the web root (along with any other file on the server that the PHP process user has the proper permissions to write) resulting a remote code execution.

CVSS 3.1
6.5 MEDIUMCVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:H/A:H
EPSS
4.15% probability · 90th percentile
CISA KEV
Not listed
Weakness
CWE-22
Affected
ritecms/ritecms
Source
cve@mitre.org

References

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.