CVE-2022-28606

critical

Description

An arbitrary file upload vulnerability exists in Wenzhou Huoyin Information Technology Co., Ltd. BossCMS 1.0, which can be exploited by an attacker to gain control of the server.

References

https://www.cnvd.org.cn/patchInfo/show/313666

https://www.cnvd.org.cn/flaw/show/CNVD-2022-04804

https://www.bosscms.net/

Details

Source: Mitre, NVD

Published: 2022-05-05

Updated: 2022-05-13

Risk Information

CVSS v2

Base Score: 7.5

Vector: CVSS2#AV:N/AC:L/Au:N/C:P/I:P/A:P

Severity: High

CVSS v3

Base Score: 9.8

Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Severity: Critical