Backdrop CMS 1.22.0 has Unrestricted File Upload vulnerability via 'themes' that allows attackers to Remote Code Execution. Note: Third parties dispute this and argue that advanced permissions are required.
References
Link | Resource |
---|---|
https://grimthereaperteam.medium.com/backdrop-cms-1-22-0-unrestricted-file-upload-themes-ad42a599561c | Exploit Third Party Advisory |
History
No history.
MITRE Information
Status: PUBLISHED
Assigner: mitre
Published: 2022-10-07T00:00:00
Updated: 2024-05-08T21:19:03.693963
Reserved: 2022-10-03T00:00:00
Link: CVE-2022-42092
JSON object: View
NVD Information
Status : Modified
Published: 2022-10-07T18:15:23.097
Modified: 2024-05-17T02:14:00.897
Link: CVE-2022-42092
JSON object: View
Redhat Information
No data.
CWE