CVE-2022-32409

CRITICAL EXPLOITED NUCLEI

Softwarepublico I3geo - Path Traversal

Title source: rule

Description

A local file inclusion (LFI) vulnerability in the component codemirror.php of Portal do Software Publico Brasileiro i3geo v7.0.5 allows attackers to execute arbitrary PHP code via a crafted HTTP request.

Nuclei Templates (1)

Portal do Software Publico Brasileiro i3geo 7.0.5 - Local File Inclusion
CRITICALVERIFIEDby pikpikcu
Shodan: http.html:"i3geo"
FOFA: body="i3geo"

Scores

CVSS v3 9.8
EPSS 0.6655
EPSS Percentile 98.5%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Details

VulnCheck KEV 2023-11-15
CWE
CWE-22
Status published
Products (1)
softwarepublico/i3geo 7.0.5
Published Jul 14, 2022
Tracked Since Feb 18, 2026