CVE-2022-42092
Backdrop CMS 1.22.0 has Unrestricted File Upload vulnerability via 'themes' that allows attackers to Remote Code Execution. Note: Third parties dispute this and argue that advanced permissions are required.
- Affected products
- Backdrop Cms
- Backdropcms Backdrop Cms
- = 1.22.0
- Fix
- Available
- CVSS 3.1
- 7.2 HIGH
- EPSS
- 1.6% (73th percentile)
- Weakness
- CWE-434
- NVD status
- Modified
- Published
- 2022-10-07
CVE-2022-42092 at NVD
1 known exploit for CVE-2022-42092
Proof-of-concept code and exploit modules indexed by Sploitus