Record summary

CVE-2022-38296 has a selected CVSS score of 9.8 (critical); EIP currently links 1 Nuclei template.

Description

Cuppa CMS v1.0 was discovered to contain an arbitrary file upload vulnerability via the File Manager.

Description source: CVE List

Exploitation context

Known exploitation

VulnCheck KEV
Listed · Mar 7, 2026 · VulnCheck
Reported exploitation
Observed · VulnCheck

Available material

Nuclei templates
1

Affected products and versions

1
ProductSourceVersion rangeStatus
VulnCheckVersion data not supplied

Nuclei templates

1
ProjectDiscoveryCRITICALCuppa CMS v1.0 - Arbitrary File UploadCVSS 9.8

Cuppa CMS v1.0 was discovered to contain an arbitrary file upload vulnerability via the File Manager.

Impact

Successful exploitation of this vulnerability can lead to remote code execution and compromise of the affected system.

Remediation

Apply the latest patch or upgrade to a newer version of Cuppa CMS to mitigate this vulnerability.

WeaknessesCWE-434
Authorstheamanrawat
Template tagscvecve2022rcecuppaintrusivecuppacmsvulnvkev
CVSS vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CPE: cpe:2.3:a:cuppacms:cuppacms:1.0:*:*:*:*:*:*:*

Source: ProjectDiscovery

References

2