9.8

CVE-2022-4446

Exploit

PHP Remote File Inclusion in tsolucio/corebos

PHP Remote File Inclusion in GitHub repository tsolucio/corebos prior to 8.0.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
CorebosCorebos Version < 8.0
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 1.27% 0.659
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 9.8 3.9 5.9
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
security@huntr.dev 9.8 3.9 5.9
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CWE-669 Incorrect Resource Transfer Between Spheres

The product does not properly transfer a resource/behavior to another sphere, or improperly imports a resource/behavior from another sphere, in a manner that provides unintended control over that resource.

CWE-98 Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion')

The PHP application receives input from an upstream component, but it does not restrict or incorrectly restricts the input before its usage in "require," "include," or similar functions.

https://github.com/tsolucio/corebos/commit/8035e725ecb397348bd50545e90975b699e4f9f2
Patch
Third Party Advisory
https://huntr.dev/bounties/718f1be6-3834-4ef2-8134-907a52009894
Patch
Third Party Advisory
Exploit
Issue Tracking