CVE-2024-22638
CRITICALliveSite 2019.1 - Remote Code Execution via edit_designer_region.php or add_email_campaign.php
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2024-22638. PoCs published by tmrswrr.
AI-analyzed exploit summary This exploit demonstrates a Remote Code Execution (RCE) vulnerability in liveSite CMS version 2019.1 by injecting PHP code into the campaign body, which is then executed by the server. The payload <?php echo system('cat /etc/passwd'); ?> is used to verify the vulnerability by reading the /etc/passwd file.
Description
liveSite v2019.1 was discovered to contain a remote code execution (RCE) vulenrabiity via the component /livesite/edit_designer_region.php or /livesite/add_email_campaign.php.
Exploits (1)
This exploit demonstrates a Remote Code Execution (RCE) vulnerability in liveSite CMS version 2019.1 by injecting PHP code into the campaign body, which is then executed by the server. The payload <?php echo system('cat /etc/passwd'); ?> is used to verify the vulnerability by reading the /etc/passwd file.
References (2)
Scores
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H