Vulnerabilities
Vulnerable Software

Vulnerability Details CVE-2022-23048

Exponent CMS 2.6.0patch2 allows an authenticated admin user to upload a malicious extension in the format of a ZIP file with a PHP file inside it. After upload it, the PHP file will be placed at "themes/simpletheme/{rce}.php" from where can be accessed in order to execute commands.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.046
EPSS Ranking 88.7%
CVSS Severity
CVSS v3 Score 7.2
CVSS v2 Score 6.5
Products affected by CVE-2022-23048


Contact Us

Shodan ® - All rights reserved