Vulnerability CVE-2022-24248


Published: 2022-04-12

Description:
RiteCMS version 3.1.0 and below suffers from an arbitrary file deletion via path traversal vulnerability in Admin Panel. Exploiting the vulnerability allows an authenticated attacker to delete any file in the web root (along with any other file on the server that the PHP process user has the proper permissions to delete). Furthermore, an attacker might leverage the capability of arbitrary file deletion to circumvent certain web server security mechanisms such as deleting .htaccess file that would deactivate those security constraints.

Type:

CWE-22

(Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal'))

CVSS2 => (AV:N/AC:L/Au:S/C:N/I:C/A:C)

CVSS Base Score
Impact Subscore
Exploitability Subscore
8.5/10
9.2/10
8/10
Exploit range
Attack complexity
Authentication
Remote
Low
Single time
Confidentiality impact
Integrity impact
Availability impact
None
Complete
Complete
Affected software
Ritecms -> Ritecms 

 References:
https://www.exploit-db.com/exploits/50615
https://en.0day.today/exploit/description/37177

Copyright 2024, cxsecurity.com

 

Back to Top