CVE-2022-47083

HIGH

Spitfire CMS <1.0.475 - Code Injection

Title source: llm

Description

A PHP Object Injection vulnerability in the unserialize() function Spitfire CMS v1.0.475 allows authenticated attackers to execute arbitrary code via sending crafted requests to the web application.

Scores

CVSS v3 8.8
EPSS 0.0094
EPSS Percentile 76.0%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Classification

CWE
CWE-502
Status published

Affected Products (1)

spitfire_project/spitfire

Timeline

Published Jan 10, 2023
Tracked Since Feb 18, 2026