Back

HIGH

Local File Inclusion in Axiell Iguana CMS

Published Jan 4, 2023

Description

A Local File Inclusion vulnerability has been found in Axiell Iguana CMS. Due to insufficient neutralisation of user input on the url parameter on the Proxy.type.php endpoint, external users are capable of accessing files on the server.

Affected products

Remediation

Vendor solution

Upgrade to the latest version of Iguana CMS.

Weaknesses (1)

References (3)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner DIVD
Published Jan 4, 2023
Updated Mar 11, 2025
Reserved Nov 8, 2022
NVD
Status Modified
Modified Jun 17, 2026
Red Hat
Severity n/a
Public date n/a
ENISA EUVD
Assigner DIVD
Published Jan 4, 2023
Updated Mar 11, 2025
Exploited since n/a
EUVD-2022-47974