HIGH
Local File Inclusion in Axiell Iguana CMS
Published Jan 4, 2023
8.8
HIGHCVSS 3.1
EPSS 0.72%
Description
A Local File Inclusion vulnerability has been found in Axiell Iguana CMS. Due to insufficient neutralisation of user input on the url parameter on the Proxy.type.php endpoint, external users are capable of accessing files on the server.
Affected products
-
- Version < 4.5.02StatusaffectedConstraints-
- Version
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
Vendor solution
Upgrade to the latest version of Iguana CMS.
Weaknesses (1)
References (3)
- https://csirt.divd.nl/CVE-2022-45052/ third-party-advisoryThird Party Advisory
- https://csirt.divd.nl/DIVD-2022-00064/ third-party-advisoryThird Party Advisory
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2022-47974 Advisory
| Link | Providers | Tags |
|---|---|---|
| https://csirt.divd.nl/CVE-2022-45052/ | third-party-advisoryThird Party Advisory | |
| https://csirt.divd.nl/DIVD-2022-00064/ | third-party-advisoryThird Party Advisory | |
| https://euvd.enisa.europa.eu/vulnerability/EUVD-2022-47974 | Advisory |
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner DIVD
Published Jan 4, 2023
Updated Mar 11, 2025
Reserved Nov 8, 2022
Link CVE-2022-45052
CISA Vulnrichment
Updated n/a
ENISA EUVD
EUVD-2022-47974 Assigner DIVD
Published Jan 4, 2023
Updated Mar 11, 2025
Exploited since n/a
Link EUVD-2022-47974