CVE Published: 17/10/2022 |
CVE Updated: 03/08/2024 |
CVE Year: 2022 Source: krcert |
Vendor: WISA corp. |
Product: Smart Wing CMS Status : PUBLISHED
CVE-2022-23770 Description
This vulnerability could allow a remote attacker to execute remote commands with improper validation of parameters of certain API constructors. Remote attackers could use this vulnerability to execute malicious commands such as directory traversal.
Metrics
CVSS Version: 3.1 |
Base Score: 8.8 HIGH Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H