CVE-2022-32409
softwarepublico i3geo Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
Record summary
CVE-2022-32409 has a selected CVSS score of 9.8 (critical); EIP currently links 1 Nuclei template.
Description
A local file inclusion (LFI) vulnerability in the component codemirror.php of Portal do Software Publico Brasileiro i3geo v7.0.5 allows attackers to execute arbitrary PHP code via a crafted HTTP request.
Exploitation context
Known exploitation
- VulnCheck KEV
- Listed · Nov 15, 2023 · VulnCheck
- Reported exploitation
- Observed · VulnCheck
Available material
- Nuclei templates
- 1
Affected products and versions
1| Product | Source | Version range | Status |
|---|---|---|---|
| VulnCheck | Version data not supplied | ||
Nuclei templates
1ProjectDiscoveryCRITICALPortal do Software Publico Brasileiro i3geo 7.0.5 - Local File InclusionCVSS 9.8
Portal do Software Publico Brasileiro i3geo 7.0.5 is vulnerable to local file inclusion in the component codemirror.php, which allows attackers to execute arbitrary PHP code via a crafted HTTP request.
Impact
An attacker can exploit this vulnerability to access sensitive information, such as configuration files, credentials, or other sensitive data stored on the server.
Remediation
Apply the latest patch or upgrade to a newer version of i3geo to fix the LFI vulnerability.
Source: ProjectDiscovery