jvn.jp
https://jvn.jp/en/jp/JVN74592196/index.html CVE-2022-42458
CRITICAL
shift-tech bingo\!cms Improper Authentication
Record summary
CVE-2022-42458 has a selected CVSS score of 9.8 (critical).
Description
Authentication bypass using an alternate path or channel vulnerability in bingo!CMS version1.7.4.1 and earlier allows a remote unauthenticated attacker to upload an arbitrary file. As a result, an arbitrary script may be executed and/or a file may be altered.
Description source: CVE List
Exploitation context
Known exploitation
- VulnCheck KEV
- Listed · Oct 11, 2022 · VulnCheck
- Reported exploitation
- Observed · VulnCheck
CISA SSVC decision
ExploitationNone
AutomatableYes
Technical impactTotal
CISA Coordinator · SSVC 2.0.3 · Evaluated Apr 23, 2025 · Source: CVE List
Affected products and versions
2| Product | Source | Version range | Status |
|---|---|---|---|
bingo!CMSBrowse Shift Tech Inc. / bingo!CMS | CVE List | version1.7.4.1 and earlier | affected |
bingo\!cmsBrowse shift-tech / bingo\!cms | VulnCheck | Version data not supplied | |
References
3nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2022-42458 bingo-cms.jp
https://www.bingo-cms.jp/information/20221011.html