PT-2021-10810 · Empirecms · Empirecms

·

CVE-2020-22937

·

Published

2021-08-17

·

Updated

2022-10-26

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions EmpireCMS version 7.5
Description A remote code execution issue in the e/install/index.php file allows attackers to execute arbitrary PHP code by writing malicious code to the install file. This enables attackers to potentially gain control over the system.
Recommendations For EmpireCMS version 7.5, consider removing or restricting access to the e/install/index.php file until a patch is available. As a temporary workaround, restrict write access to the install file to prevent malicious code from being written.

Exploit

Fix

RCE

Code Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2020-22937

Affected Products

Empirecms