CVE Published: 07/12/2022 |
CVE Updated: 03/08/2024 |
CVE Year: 2022 Source: jpcert |
Vendor: Shift Tech Inc. |
Product: bingo!CMS Status : PUBLISHED
CVE-2022-42458 Description
Authentication bypass using an alternate path or channel vulnerability in bingo!CMS version1.7.4.1 and earlier allows a remote unauthenticated attacker to upload an arbitrary file. As a result, an arbitrary script may be executed and/or a file may be altered.