Vulnerability Details CVE-2022-26271
74cmsSE v3.4.1 was discovered to contain an arbitrary file read vulnerability via the $url parameter at \index\controller\Download.php.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.098
EPSS Ranking 92.5%
CVSS Severity
CVSS v3 Score 7.5
CVSS v2 Score 5.0
Products affected by CVE-2022-26271
-
cpe:2.3:a:74cms:74cms:3.4.1