CVE-2022-41573
CVSS 3.1 Score 9.8 of 10 (high)
Details
Published Jan 7, 2025
Updated: Jan 8, 2025
CWE ID 434
Summary
CVE-2022-41573 is a vulnerability affecting Ovidentia version 8.3. This issue permits remote code execution due to a flaw in the file upload feature. Users are able to upload executable files, such as a .png file containing PHP code. After uploading, the file can be renamed with a .php extension, which grants access to the malicious code at an "images/common/" URI. This vulnerability poses a serious security risk and should be addressed promptly by updating to a patched version of Ovidentia.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.