Vulnerability Description
An arbitrary file upload vulnerability in the apiImportLabs function in api_labs.php of EVE-NG 2.0.3-112 Community allows attackers to execute arbitrary code via a crafted UNL file.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Eve-Ng | Eve-Ng | 2.0.3-112 |
Related Weaknesses (CWE)
References
- http://eve-ng.comVendor Advisory
- https://erpaciocco.github.io/2022/eve-ng-rce/ExploitThird Party Advisory
- http://eve-ng.comVendor Advisory
- https://erpaciocco.github.io/2022/eve-ng-rce/ExploitThird Party Advisory
FAQ
What is CVE-2022-31366?
CVE-2022-31366 is a vulnerability with a CVSS score of 7.2 (HIGH). An arbitrary file upload vulnerability in the apiImportLabs function in api_labs.php of EVE-NG 2.0.3-112 Community allows attackers to execute arbitrary code via a crafted UNL file.
How severe is CVE-2022-31366?
CVE-2022-31366 has been rated HIGH with a CVSS base score of 7.2/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2022-31366?
Check the references section above for vendor advisories and patch information. Affected products include: Eve-Ng Eve-Ng.