CVE | CVE-2022-4136 |
CVE Title | |
Published Date | 2022-11-24T08:15Z |
Modified Date | 2022-11-30T19:52Z |
CWE Type | NVD-CWE-Other |
CVSS 3.x | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Description | Dangerous method exposed which can lead to RCE in qmpass/leadshop v1.4.15 allows an attacker to control the target host by calling any function in leadshop.php via the GET method. |
References | |
By clicking these links you will leave this website. We do not endorse and will not be held accountable for any activity on external sites. | |
Reference URL | https://huntr.dev/bounties/fe418ae1-7c80-4d91-8a5a-923d60ba78c3 |
Reference Description | CONFIRM https://huntr.dev/bounties/fe418ae1-7c80-4d91-8a5a-923d60ba78c3 |
Reference URL | https://github.com/qmpaas/leadshop/commit/f27e9ca5c93eaadda1097396b65c234b16186d67 |
Reference Description | MISC https://github.com/qmpaas/leadshop/commit/f27e9ca5c93eaadda1097396b65c234b16186d67 |
Tags | Exploit Patch Third Party Advisory |
Sources | NIST MITRE |