Command Injection Vulnerability in PowerCMS by Alfasado Inc.
CVE-2022-33941
9.8CRITICAL
What is CVE-2022-33941?
The PowerCMS XMLRPC API is vulnerable to command injection due to improper input validation. This vulnerability allows an attacker to send a specially crafted POST request, leading to the execution of arbitrary Perl scripts or OS commands. It affects multiple versions of PowerCMS, including the 6 Series, 5 Series, and 4 Series, along with all unsupported versions of the 3 Series.
Affected Version(s)
PowerCMS XMLRPC API PowerCMS 6.021 and earlier (PowerCMS 6 Series), PowerCMS 5.21 and earlier (PowerCMS 5 Series), PowerCMS 4.51 and earlier (PowerCMS 4 Series), and PowerCMS 3 Series and earlier which are unsupported (End-of-Life, EOL)
