Record summary

CVE-2022-31854 has a selected CVSS score of 7.2 (high); EIP currently links 1 catalogued exploit, 1 repository PoC, and 1 Nuclei template.

Description

Codoforum v5.1 was discovered to contain an arbitrary file upload vulnerability via the logo change option in the admin panel.

Description source: CVE List

Exploitation context

Available material

Catalogued exploits
1
Repository PoCs
1
Nuclei templates
1

Proofs of concept

2

Catalogued exploits

ExploitDBCodoForum v5.1 - Remote Code Execution (RCE)ExploitDB exploitby Krish PandeyNot analyzed1 file
ExploitDB

PoC details

Repository PoCs

GitHubVikaran101/CVE-2022-31854Repository PoCby Vikaran101Stars: 5Not analyzed2 files

8.1 KiB

GitHub

PoC details

Nuclei templates

1
ProjectDiscoveryHIGHCodoforum 5.1 - Arbitrary File UploadCVSS 7.2

Codoforum 5.1 contains an arbitrary file upload vulnerability via the logo change option in the admin panel. An attacker can upload arbitrary files to the server, which in turn can be used to make the application execute file content as code. As a result, an attacker can potentially obtain sensitive information, modify data, and/or execute unauthorized operations.

Impact

Successful exploitation of this vulnerability can result in unauthorized remote code execution on the affected system.

Remediation

Apply the latest security patch or upgrade to a patched version of Codoforum.

WeaknessesCWE-434
Authorstheamanrawat
Template tagscvecve2022rcecodoforumrceauthenticatedintrusivecodologicvuln
CVSS vector: CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
CPE: cpe:2.3:a:codologic:codoforum:5.1:*:*:*:*:*:*:*

Source: ProjectDiscovery

References

5