Lucene search

K
cve[email protected]CVE-2022-1657
HistoryJun 13, 2022 - 2:15 p.m.

CVE-2022-1657

2022-06-1314:15:08
CWE-22
web.nvd.nist.gov
60
4
cve-2022-1657
jupiter
jupiterx
theme
path traversal
local file inclusion
security vulnerability
nvd

6.5 Medium

CVSS2

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

SINGLE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:L/Au:S/C:P/I:P/A:P

8.8 High

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

8.4 High

AI Score

Confidence

High

0.001 Low

EPSS

Percentile

27.9%

Vulnerable versions of the Jupiter (<= 6.10.1) and JupiterX (<= 2.0.6) Themes allow logged-in users, including subscriber-level users, to perform Path Traversal and Local File inclusion. In the JupiterX theme, the jupiterx_cp_load_pane_action AJAX action present in the lib/admin/control-panel/control-panel.php file calls the load_control_panel_pane function. It is possible to use this action to include any local PHP file via the slug parameter. The Jupiter theme has a nearly identical vulnerability which can be exploited via the mka_cp_load_pane_action AJAX action present in the framework/admin/control-panel/logic/functions.php file, which calls the mka_cp_load_pane_action function.

Affected configurations

Vulners
NVD
Node
artbeesjupiterRange6.10.16.10.1
OR
artbeesjupiter_x_coreRange2.0.62.0.6
VendorProductVersionCPE
artbeesjupiter*cpe:2.3:a:artbees:jupiter:*:*:*:*:*:*:*:*
artbeesjupiter_x_core*cpe:2.3:a:artbees:jupiter_x_core:*:*:*:*:*:*:*:*

CNA Affected

[
  {
    "product": "Jupiter",
    "vendor": "ArtBees",
    "versions": [
      {
        "lessThanOrEqual": "6.10.1",
        "status": "affected",
        "version": "6.10.1",
        "versionType": "custom"
      }
    ]
  },
  {
    "product": "Jupiter X",
    "vendor": "ArtBees",
    "versions": [
      {
        "lessThanOrEqual": "2.0.6",
        "status": "affected",
        "version": "2.0.6",
        "versionType": "custom"
      }
    ]
  }
]

Social References

More

6.5 Medium

CVSS2

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

SINGLE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:L/Au:S/C:P/I:P/A:P

8.8 High

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

8.4 High

AI Score

Confidence

High

0.001 Low

EPSS

Percentile

27.9%