Vulnerability Description
Authentication bypass using an alternate path or channel vulnerability in bingo!CMS version1.7.4.1 and earlier allows a remote unauthenticated attacker to upload an arbitrary file. As a result, an arbitrary script may be executed and/or a file may be altered.
CVSS Score
CRITICAL
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Shift-Tech | Bingo\!Cms | <= 1.7.4.1 |
Related Weaknesses (CWE)
References
- https://jvn.jp/en/jp/JVN74592196/index.htmlThird Party Advisory
- https://www.bingo-cms.jp/information/20221011.htmlVendor Advisory
- https://jvn.jp/en/jp/JVN74592196/index.htmlThird Party Advisory
- https://www.bingo-cms.jp/information/20221011.htmlVendor Advisory
FAQ
What is CVE-2022-42458?
CVE-2022-42458 is a vulnerability with a CVSS score of 9.8 (CRITICAL). Authentication bypass using an alternate path or channel vulnerability in bingo!CMS version1.7.4.1 and earlier allows a remote unauthenticated attacker to upload an arbitrary file. As a result, an arb...
How severe is CVE-2022-42458?
CVE-2022-42458 has been rated CRITICAL with a CVSS base score of 9.8/10. This is considered a critical vulnerability requiring immediate attention.
Is there a patch for CVE-2022-42458?
Check the references section above for vendor advisories and patch information. Affected products include: Shift-Tech Bingo\!Cms.