Command Injection Vulnerability in PowerCMS by Alfasado Inc.
CVE-2022-33941

9.8CRITICAL

Key Information:

Vendor
CVE Published:
8 September 2022

What is CVE-2022-33941?

The PowerCMS XMLRPC API is vulnerable to command injection due to improper input validation. This vulnerability allows an attacker to send a specially crafted POST request, leading to the execution of arbitrary Perl scripts or OS commands. It affects multiple versions of PowerCMS, including the 6 Series, 5 Series, and 4 Series, along with all unsupported versions of the 3 Series.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.

Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.

Affected Version(s)

PowerCMS XMLRPC API PowerCMS 6.021 and earlier (PowerCMS 6 Series), PowerCMS 5.21 and earlier (PowerCMS 5 Series), PowerCMS 4.51 and earlier (PowerCMS 4 Series), and PowerCMS 3 Series and earlier which are unsupported (End-of-Life, EOL)

References

EPSS Score

5% chance of being exploited in the next 30 days.

CVSS V3.1

Score:
9.8
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.