CVE-2022-45544
RCETitle: Schlix Cms RCE
RCE
Proof Of Concept
PoC Available for CVE-2022-45544
CWE Category
CWE-863
Published Date
Feb 07, 2023
Modified Date
Nov 21, 2024
Exploit Status
Available
Score
8.8
CVSS v3.1
Exploit Probability (EPSS)
1.32%
Vulnerability Summary
CVE-2022-45544: Insecure Permission vulnerability in Schlix Web Inc SCHLIX CMS 2.2.7-2 allows attacker to upload arbitrary files and execute arbitrary code via the tristao parameter. NOTE: this is disputed by the vendor because an admin is intentionally allowed to upload new executable PHP code, such as a theme that was obtained from a trusted source or was developed for their own website. Only an admin can upload such code, not someone else in an "attacker" role.
Impacted Vendors
Reference Links
https://blog.tristaomarinho.com/schlix-cms-2-2-7-2-arbitrary-file-upload/
https://github.com/tristao-marinho/CVE-2022-45544/blob/main/README.md
https://www.schlix.com/
https://www.schlix.com/downloads/schlix-cms/schlix-cms-v2.2.7-2.zip
https://blog.tristaomarinho.com/schlix-cms-2-2-7-2-arbitrary-file-upload/
https://github.com/tristao-marinho/CVE-2022-45544/blob/main/README.md
https://www.schlix.com/
https://www.schlix.com/downloads/schlix-cms/schlix-cms-v2.2.7-2.zip
CVSS v3.1
Source Entity
[email protected]
Severity
HIGH
8.8
Attack Vector
NETWORK
Complexity
LOW
Privileges
N/A
Interaction
NONE
Confidentiality
N/A
Integrity
N/A
Availability
N/A
Scope
UNCHANGED
RAW VECTOR
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CVSS v3.1
Source Entity
134c704f-9b21-4f2e-91b3-4a467353bcc0
Severity
HIGH
8.8
Attack Vector
NETWORK
Complexity
LOW
Privileges
N/A
Interaction
NONE
Confidentiality
N/A
Integrity
N/A
Availability
N/A
Scope
UNCHANGED
RAW VECTOR
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Associated Attack Patterns (CAPEC)
Total: PatternsNo specific attack patterns mapped.
Likelihood
Severity
Page /
CVE-2022-45544 Exploits & PoCs (Proof Of Concept)
GitHub
https://github.com/tristao-io/CVE-2022-45544
MODIFIED
Vulnerability data or affected products updated.
PUBLISHED
Vulnerability first announced in NVD.
Attack Vector Matrix
Access Vector
NETWORK
Complexity
LOW
Privileges
N/A
Interaction
NONE
CVSS Vector String
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Affected Stack
No specific products linked.