Início
Início
Tendências
Tendências
Vulnerabilidades
Vulnerabilidades
Notícias
Notícias
Pesquisadores
Pesquisadores
Por que dbugs?
Por que dbugs?
Configurações

Mzwebo

#40841de 56,338
7.2CVSS total
Vulnerabilidades · 1
PT-2023-14430
7.2
2023-01-03
Unknown · B2Evolution · CVE-2022-44036
**Name of the Vulnerable Software and Affected Versions** b2evolution version 7.2.5 **Description** The issue allows for arbitrary file upload, leading to command execution, when configured with `admins can manipulate sensitive files`. This is considered a feature by the vendor, but it can be exploited by attackers to execute remote commands. The vendor suggests that disabling the feature is an obvious solution for those who do not want it. **Recommendations** For b2evolution version 7.2.5, consider disabling the `admins can manipulate sensitive files` feature to prevent arbitrary file upload and command execution.