Vulnerability Description
The copy function of the file manager in Cuppa CMS v1.0 allows any file to be copied to the current directory, granting attackers read access to arbitrary files.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Cuppacms | Cuppacms | 1.0 |
References
- https://github.com/dota-st/Vulnerability/blob/master/CuppaCMS/CuppaCMS_second.mdExploitThird Party Advisory
- https://github.com/dota-st/Vulnerability/blob/master/CuppaCMS/CuppaCMS_second.mdExploitThird Party Advisory
FAQ
What is CVE-2022-25401?
CVE-2022-25401 is a vulnerability with a CVSS score of 7.5 (HIGH). The copy function of the file manager in Cuppa CMS v1.0 allows any file to be copied to the current directory, granting attackers read access to arbitrary files.
How severe is CVE-2022-25401?
CVE-2022-25401 has been rated HIGH with a CVSS base score of 7.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2022-25401?
Check the references section above for vendor advisories and patch information. Affected products include: Cuppacms Cuppacms.