Record summary

CVE-2022-32409 has a selected CVSS score of 9.8 (critical); EIP currently links 1 Nuclei template.

Description

A local file inclusion (LFI) vulnerability in the component codemirror.php of Portal do Software Publico Brasileiro i3geo v7.0.5 allows attackers to execute arbitrary PHP code via a crafted HTTP request.

Description source: CVE List

Exploitation context

Known exploitation

VulnCheck KEV
Listed · Nov 15, 2023 · VulnCheck
Reported exploitation
Observed · VulnCheck

Available material

Nuclei templates
1

Affected products and versions

1
ProductSourceVersion rangeStatus
VulnCheckVersion data not supplied

Nuclei templates

1
ProjectDiscoveryCRITICALPortal do Software Publico Brasileiro i3geo 7.0.5 - Local File InclusionCVSS 9.8

Portal do Software Publico Brasileiro i3geo 7.0.5 is vulnerable to local file inclusion in the component codemirror.php, which allows attackers to execute arbitrary PHP code via a crafted HTTP request.

Impact

An attacker can exploit this vulnerability to access sensitive information, such as configuration files, credentials, or other sensitive data stored on the server.

Remediation

Apply the latest patch or upgrade to a newer version of i3geo to fix the LFI vulnerability.

WeaknessesCWE-22
Authorspikpikcu
Template tagscve2022cvei3geolfisoftwarepublicovkevvuln
CVSS vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CPE: cpe:2.3:a:softwarepublico:i3geo:7.0.5:*:*:*:*:*:*:*
Shodan: http.html:"i3geo"
FOFA: body="i3geo"

Source: ProjectDiscovery

References

3