An issue was discovered in CandyCMS version 1.0.0, allows remote attackers to execute arbitrary code via the install.php component.
Advisories
No advisories yet.
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
| Link | Providers |
|---|---|
| https://www.xuxblog.top/2024/03/25/CandyCMS-Pre-Auth-RCE/ |
|
History
Thu, 22 May 2025 14:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Steve228uk
Steve228uk candycms |
|
| CPEs | cpe:2.3:a:steve228uk:candycms:1.0.0:*:*:*:*:*:*:* | |
| Vendors & Products |
Candy
Candy candycms |
Steve228uk
Steve228uk candycms |
Fri, 18 Apr 2025 19:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Candy
Candy candycms |
|
| CPEs | cpe:2.3:a:candy:candycms:1.0.0:*:*:*:*:*:*:* | |
| Vendors & Products |
Candy
Candy candycms |
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2024-08-02T01:46:04.333Z
Reserved: 2024-03-27T00:00:00
Link: CVE-2024-31022
Updated: 2024-08-02T01:46:04.333Z
Status : Analyzed
Published: 2024-04-08T06:15:07.690
Modified: 2025-05-22T14:28:25.127
Link: CVE-2024-31022
No data.
OpenCVE Enrichment
No data.
Weaknesses