Vulnerability Details CVE-2022-30037
XunRuiCMS v4.3.3 to v4.5.1 vulnerable to PHP file write and CMS PHP file inclusion, allows attackers to execute arbitrary php code, via the add function in cron.php.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.001
EPSS Ranking 25.6%
CVSS Severity
CVSS v3 Score 7.2
Products affected by CVE-2022-30037
-
cpe:2.3:a:xunruicms:xunruicms:4.3.10
-
cpe:2.3:a:xunruicms:xunruicms:4.3.11
-
cpe:2.3:a:xunruicms:xunruicms:4.3.12
-
cpe:2.3:a:xunruicms:xunruicms:4.3.13
-
cpe:2.3:a:xunruicms:xunruicms:4.3.14
-
cpe:2.3:a:xunruicms:xunruicms:4.3.3
-
cpe:2.3:a:xunruicms:xunruicms:4.3.4
-
cpe:2.3:a:xunruicms:xunruicms:4.3.5
-
cpe:2.3:a:xunruicms:xunruicms:4.3.6
-
cpe:2.3:a:xunruicms:xunruicms:4.3.7
-
cpe:2.3:a:xunruicms:xunruicms:4.3.8
-
cpe:2.3:a:xunruicms:xunruicms:4.3.9
-
cpe:2.3:a:xunruicms:xunruicms:4.5.0
-
cpe:2.3:a:xunruicms:xunruicms:4.5.1