Vulnerability Description
An issue was discovered in taoCMS v3.0.2. There is an arbitrary file read vulnerability that can read any files via admin.php?action=file&ctrl=download&path=../../1.txt.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Taogogo | Taocms | 3.0.2 |
Related Weaknesses (CWE)
References
- https://github.com/taogogo/taocms/issues/15ExploitThird Party Advisory
- https://github.com/taogogo/taocms/issues/15ExploitThird Party Advisory
FAQ
What is CVE-2022-23316?
CVE-2022-23316 is a vulnerability with a CVSS score of 4.9 (MEDIUM). An issue was discovered in taoCMS v3.0.2. There is an arbitrary file read vulnerability that can read any files via admin.php?action=file&ctrl=download&path=../../1.txt.
How severe is CVE-2022-23316?
CVE-2022-23316 has been rated MEDIUM with a CVSS base score of 4.9/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2022-23316?
Check the references section above for vendor advisories and patch information. Affected products include: Taogogo Taocms.