Remote Code Execution in Exponent CMS by Malicious ZIP Upload
CVE-2022-23048
7.2HIGH
What is CVE-2022-23048?
Exponent CMS 2.6.0patch2 includes a vulnerability that permits an authenticated admin user to upload a ZIP file containing a PHP file, which enables remote code execution. Once uploaded, the PHP file is accessible at 'themes/simpletheme/{rce}.php', allowing unauthorized command execution on the server.
Affected Version(s)
Exponent CMS v2.6.0patch2
