CVE-2023-1046

MEDIUM

MuYuCMS 2.2 - Server-Side Request Forgery via getFile url Parameter

Title source: manual
STIX 2.1

Description

A vulnerability classified as critical has been found in MuYuCMS 2.2. This affects an unknown part of the file /admin.php/update/getFile.html. The manipulation of the argument url leads to server-side request forgery. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-221805 was assigned to this vulnerability.

References (3)

Core 3
Core References
Permissions Required vdb-entry technical-description
https://vuldb.com/?id.221805
Permissions Required signature permissions-required
https://vuldb.com/?ctiid.221805
Exploit, Issue Tracking, Third Party Advisory exploit issue-tracking
https://github.com/MuYuCMS/MuYuCMS/issues/7

Scores

CVSS v3 6.3
EPSS 0.0060
EPSS Percentile 44.2%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L

Details

CWE
CWE-918
Status published
Products (1)
muyucms/muyucms 2.2
Published Feb 26, 2023
Tracked Since Feb 18, 2026