Sunlogin Sunflower Simplified (aka Sunflower Simple and Personal) 1.0.1.43315 is vulnerable to a path traversal issue. A remote and unauthenticated attacker can execute arbitrary programs on the victim host by sending a crafted HTTP request, as demonstrated by /check?cmd=ping../ followed by the pathname of the powershell.exe program.
Advisories
No advisories yet.
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Fri, 21 Mar 2025 15:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2025-03-21T14:43:30.439Z
Reserved: 2023-02-13T00:00:00.000Z
Link: CVE-2022-48323
Updated: 2024-08-03T15:10:59.817Z
Status : Modified
Published: 2023-02-13T05:15:13.333
Modified: 2025-03-21T15:15:38.253
Link: CVE-2022-48323
No data.
OpenCVE Enrichment
No data.
Weaknesses