Record summary

CVE-2022-0415 has a selected CVSS score of 8.8 (high); EIP currently links 1 Nuclei template.

Description

Remote Command Execution in uploading repository file in GitHub repository gogs/gogs prior to 0.12.6.

Description source: CVE List

Exploitation context

Available material

Nuclei templates
1

Affected products and versions

2
ProductSourceVersion rangeStatus
CVE ListBefore 0.12.6affected
GitHub AdvisoryBefore 0.12.6 · Fixed in 0.12.6affected

Nuclei templates

1
ProjectDiscoveryHIGHGogs <0.12.6 - Remote Command ExecutionCVSS 8.8

Gogs before 0.12.6 is susceptible to remote command execution via the uploading repository file in GitHub repository gogs/gogs. An attacker can execute malware, obtain sensitive information, modify data, and/or gain full control over a compromised system without entering necessary credentials.

Impact

Successful exploitation of this vulnerability allows remote attackers to execute arbitrary commands on the target system.

Remediation

Fixed in version 0.12.6.

WeaknessesCWE-434CWE-20
Authorstheamanrawat
Template tagscvecve2022rcegogsauthenticatedhuntrintrusivevuln
CVSS vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CPE: cpe:2.3:a:gogs:gogs:*:*:*:*:*:*:*:*
Shodan: cpe:"cpe:2.3:a:gogs:gogs"
Shodan: http.title:"sign in - gogs"
FOFA: title="sign in - gogs"
Google: intitle:"sign in - gogs"

Source: ProjectDiscovery

References

7