Lucene search

K
cnvdChina National Vulnerability DatabaseCNVD-2022-18424
HistoryMar 03, 2022 - 12:00 a.m.

AyaCMS Remote Code Execution Vulnerability

2022-03-0300:00:00
China National Vulnerability Database
www.cnvd.org.cn
19
ayacms
remote code execution
vulnerability
php
website builder
filter failure
exploit

EPSS

0.004

Percentile

72.5%

AyaCms is an extremely simple and free open source Php website builder. A remote code execution vulnerability exists in AyaCMS version 3.1.2, which stems from a failure to properly filter special elements in the /aya/module/admin/ust_tab_e.inc.php page. An attacker could exploit this vulnerability to cause remote code execution.

EPSS

0.004

Percentile

72.5%

Related for CNVD-2022-18424