Lucene search

K
cveMitreCVE-2022-46101
HistoryDec 22, 2022 - 6:15 p.m.

CVE-2022-46101

2022-12-2218:15:09
CWE-94
mitre
web.nvd.nist.gov
29
ayacms
v3.1.2
ust_sql.inc.php
code flaw
command execution
security vulnerability

CVSS3

8.8

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

AI Score

8.7

Confidence

High

EPSS

0.001

Percentile

43.2%

AyaCMS v3.1.2 was found to have a code flaw in the ust_sql.inc.php file, which allows attackers to cause command execution by inserting malicious code.

Affected configurations

Nvd
Node
ayacms_projectayacmsMatch3.1.2
VendorProductVersionCPE
ayacms_projectayacms3.1.2cpe:2.3:a:ayacms_project:ayacms:3.1.2:*:*:*:*:*:*:*

CVSS3

8.8

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

AI Score

8.7

Confidence

High

EPSS

0.001

Percentile

43.2%

Related for CVE-2022-46101