CVE-2023-1482
A vulnerability, which was classified as problematic, was found in HkCms 2.2.4.230206.
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (0.77%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
A vulnerability, which was classified as problematic, was found in HkCms 2.2.4.230206. This affects an unknown part of the file /admin.php/appcenter/local.html?type=addon of the component External Plugin Handler. The manipulation leads to code injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-223365 was assigned to this vulnerability.
- CVSS 3.1
- 8.8 HIGHCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
- EPSS
- 0.77% probability · 54th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-94
- Affected
- hkcms project/hkcms
- Source
- cna@vuldb.com
References
- https://gitee.com/Hk_Cms/HkCms/issues/I6J7ZDExploit, Issue Tracking, Third Party Advisory
- https://vuldb.com/?ctiid.223365Third Party Advisory
- https://vuldb.com/?id.223365Third Party Advisory
- https://gitee.com/Hk_Cms/HkCms/issues/I6J7ZDExploit, Issue Tracking, Third Party Advisory
- https://vuldb.com/?ctiid.223365Third Party Advisory
- https://vuldb.com/?id.223365Third Party Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.