Vulnerability Description
VIAVIWEB Wallpaper Admin 1.0 contains an unauthenticated remote code execution vulnerability in the image upload functionality. Attackers can upload a malicious PHP file through the add_gallery_image.php endpoint to execute arbitrary code on the server.
CVSS Score
CRITICAL
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Viaviweb | Wallpaper Admin | 1.0 |
Related Weaknesses (CWE)
References
- https://www.exploit-db.com/exploits/51033ExploitThird Party AdvisoryVDB Entry
- https://www.viaviweb.comProduct
- https://www.vulncheck.com/advisories/viaviweb-wallpaper-admin-code-execution-viaThird Party Advisory
FAQ
What is CVE-2022-50893?
CVE-2022-50893 is a vulnerability with a CVSS score of 9.8 (CRITICAL). VIAVIWEB Wallpaper Admin 1.0 contains an unauthenticated remote code execution vulnerability in the image upload functionality. Attackers can upload a malicious PHP file through the add_gallery_image....
How severe is CVE-2022-50893?
CVE-2022-50893 has been rated CRITICAL with a CVSS base score of 9.8/10. This is considered a critical vulnerability requiring immediate attention.
Is there a patch for CVE-2022-50893?
Check the references section above for vendor advisories and patch information. Affected products include: Viaviweb Wallpaper Admin.