Arbitrary File Upload Vulnerability in bloofoxCMS by bloofox
CVE-2022-28528
8.8HIGH
What is CVE-2022-28528?
bloofoxCMS version 0.5.2.1 contains an arbitrary file upload vulnerability that allows malicious actors to upload arbitrary files through the administration interface. This vulnerability is triggered via a specific request to /admin/index.php?mode=content&page=media&action=edit, potentially allowing unauthorized file execution or further exploitation of the system. Addressing this issue is essential to maintaining the security and integrity of the application.
