In b2evolution 7.2.5, if configured with admins_can_manipulate_sensitive_files, arbitrary file upload is allowed for admins, leading to command execution. NOTE: the vendor's position is that this is "very obviously a feature not an issue and if you don't like that feature it is very obvious how to disable it."
Advisories
No advisories yet.
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
| Link | Providers |
|---|---|
| https://github.com/b2evolution/b2evolution/issues/121 |
|
History
Mon, 14 Jul 2025 13:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
epss
|
epss
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2024-08-03T13:47:05.499Z
Reserved: 2022-10-30T00:00:00
Link: CVE-2022-44036
Updated: 2024-08-03T13:47:05.499Z
Status : Modified
Published: 2023-01-03T21:15:12.880
Modified: 2024-11-21T07:27:34.987
Link: CVE-2022-44036
No data.
OpenCVE Enrichment
No data.
Weaknesses