VulnerabilityModified
CVE-2022-24247
RiteCMS version 3.1.0 and below suffers from an arbitrary file overwrite via path traversal vulnerability in Admin Panel.
MEDIUM 6.5EPSS 4.15%
Does this matter?
Lower severity and a low EPSS score (4.15%). Track it; it rarely justifies an emergency change on its own.
Description
RiteCMS version 3.1.0 and below suffers from an arbitrary file overwrite via path traversal vulnerability in Admin Panel. Exploiting the vulnerability allows an authenticated attacker to overwrite any file in the web root (along with any other file on the server that the PHP process user has the proper permissions to write) resulting a remote code execution.
- CVSS 3.1
- 6.5 MEDIUMCVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:H/A:H
- EPSS
- 4.15% probability · 90th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-22
- Affected
- ritecms/ritecms
- Source
- cve@mitre.org
References
- https://cxsecurity.com/issue/WLB-2022010019Exploit, Third Party Advisory
- https://www.exploit-db.com/exploits/50614Exploit, Third Party Advisory, VDB Entry
- https://cxsecurity.com/issue/WLB-2022010019Exploit, Third Party Advisory
- https://www.exploit-db.com/exploits/50614Exploit, Third Party Advisory, VDB Entry
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.