packetstormsecurity.com
http://packetstormsecurity.com/files/170245/Syncovery-For-Linux-Web-GUI-Authenticated-Remote-Command-Execution.html CVE-2022-36534
HIGH
Syncovery For Linux Web-GUI Authenticated Remote Command Execution
Record summary
CVE-2022-36534 has a selected CVSS score of 8.8 (high); EIP currently links 1 catalogued exploit.
Description
Super Flexible Software GmbH & Co. KG Syncovery 9 for Linux v9.47x and below was discovered to contain multiple remote code execution (RCE) vulnerabilities via the Job_ExecuteBefore and Job_ExecuteAfter parameters at post_profilesettings.php.
Description source: CVE List
Exploitation context
Available material
- Catalogued exploits
- 1
Proofs of concept
1Catalogued exploits
MetasploitSyncovery For Linux Web-GUI Authenticated Remote Command ExecutionMetasploit exploitby Jan RudeNot analyzed1 file
References
5super.com
http://super.com/ syncovery.com
http://syncovery.com/ nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2022-36534 mgm-sp.com
https://www.mgm-sp.com/en/multiple-vulnerabilities-in-syncovery-for-linux