CVE-2022-31854
CodoForum v5.1 - Remote Code Execution (RCE)
Record summary
CVE-2022-31854 has a selected CVSS score of 7.2 (high); EIP currently links 1 catalogued exploit, 1 repository PoC, and 1 Nuclei template.
Proofs of concept
2Catalogued exploits
ExploitDBCodoForum v5.1 - Remote Code Execution (RCE)ExploitDB exploitby Krish PandeyNot analyzed1 file
Repository PoCs
GitHubVikaran101/CVE-2022-31854Repository PoCby Vikaran101Stars: 5Not analyzed2 files
Nuclei templates
1ProjectDiscoveryHIGHCodoforum 5.1 - Arbitrary File UploadCVSS 7.2
Codoforum 5.1 contains an arbitrary file upload vulnerability via the logo change option in the admin panel. An attacker can upload arbitrary files to the server, which in turn can be used to make the application execute file content as code. As a result, an attacker can potentially obtain sensitive information, modify data, and/or execute unauthorized operations.
Impact
Successful exploitation of this vulnerability can result in unauthorized remote code execution on the affected system.
Remediation
Apply the latest security patch or upgrade to a patched version of Codoforum.
Source: ProjectDiscovery