Command Injection Vulnerability in PowerCMS by Alfasado Inc.
CVE-2022-33941
What is CVE-2022-33941?
The PowerCMS XMLRPC API is vulnerable to command injection due to improper input validation. This vulnerability allows an attacker to send a specially crafted POST request, leading to the execution of arbitrary Perl scripts or OS commands. It affects multiple versions of PowerCMS, including the 6 Series, 5 Series, and 4 Series, along with all unsupported versions of the 3 Series.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
PowerCMS XMLRPC API PowerCMS 6.021 and earlier (PowerCMS 6 Series), PowerCMS 5.21 and earlier (PowerCMS 5 Series), PowerCMS 4.51 and earlier (PowerCMS 4 Series), and PowerCMS 3 Series and earlier which are unsupported (End-of-Life, EOL)
References
EPSS Score
5% chance of being exploited in the next 30 days.
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved
