Exponent CMS 2.6.0patch2 allows an authenticated admin user to upload a malicious extension in the format of a ZIP file with a PHP file inside it. After upload it, the PHP file will be placed at "themes/simpletheme/{rce}.php" from where can be accessed in order to execute commands.
History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: Fluid Attacks

Published: 2022-02-09T22:03:58

Updated: 2024-08-03T03:28:43.253Z

Reserved: 2022-01-10T00:00:00

Link: CVE-2022-23048

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Analyzed

Published: 2022-02-09T23:15:19.570

Modified: 2022-02-17T02:06:03.663

Link: CVE-2022-23048

cve-icon Redhat

No data.