Vulnerability CVE-2022-37190


Published: 2022-09-13   Modified: 2022-09-14

Description:
CuppaCMS 1.0 is vulnerable to Remote Code Execution (RCE). An authenticated user can control both parameters (action and function) from "/api/index.php.

 References:
https://github.com/CuppaCMS/CuppaCMS/issues/22
https://github.com/badru8612/Authenticated-RCE-CuppaCMS

Copyright 2026, cxsecurity.com

 

Back to Top