CVE-2022-43030

Siyucms v6.1.7 was discovered to contain a remote code execution (RCE) vulnerability in the background. SIYUCMS is a content management system based on ThinkPaP5 AdminLTE. SIYUCMS has a background command execution vulnerability, which can be used by attackers to gain server privileges
References
Link Resource
https://github.com/cai-niao98/siyu Exploit Third Party Advisory
https://github.com/cai-niao98/siyu/blob/main/README.md Exploit Third Party Advisory
Configurations

Configuration 1 (hide)

cpe:2.3:a:siyucms:siyucms:6.1.7:*:*:*:*:*:*:*

History

17 Nov 2022, 21:07

Type Values Removed Values Added
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 7.2
References (MISC) https://github.com/cai-niao98/siyu/blob/main/README.md - (MISC) https://github.com/cai-niao98/siyu/blob/main/README.md - Exploit, Third Party Advisory
References (MISC) https://github.com/cai-niao98/siyu - (MISC) https://github.com/cai-niao98/siyu - Exploit, Third Party Advisory
CPE cpe:2.3:a:siyucms:siyucms:6.1.7:*:*:*:*:*:*:*
CWE CWE-521
First Time Siyucms
Siyucms siyucms

14 Nov 2022, 23:15

Type Values Removed Values Added
New CVE

Information

Published : 2022-11-14 23:15

Updated : 2023-12-10 14:35


NVD link : CVE-2022-43030

Mitre link : CVE-2022-43030

CVE.ORG link : CVE-2022-43030


JSON object : View

Products Affected

siyucms

  • siyucms
CWE
CWE-521

Weak Password Requirements