CVE-2022-2419
high · 8A vulnerability was found in URVE Web Manager. It has been declared as critical. This vulnerability affects unknown code of the file _internal/collector/upload.php. The manipulation leads to unrestricted upload. Access to the local network is required for this attack to succeed. The exploit has been disclosed to the public and may be used.
8
CVSS
12.8%
EPSS (exploit prob.)
96th
EPSS percentile
2022-07-15
Published
CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Weaknesses
CWE-434
Affected products
| Vendor | Product | Affected versions |
|---|---|---|
| eveo | urve_web_manager | all versions |
Check a specific version with /api/v1/cve/match.
References
- https://github.com/joinia/webray.com.cn/blob/main/URVE/URVE%20Web%20Manager%20upload.php%20File%20upload%20vulnerability.md
- https://vuldb.com/?id.203902
- https://github.com/joinia/webray.com.cn/blob/main/URVE/URVE%20Web%20Manager%20upload.php%20File%20upload%20vulnerability.md
- https://vuldb.com/?id.203902
Query this programmatically:
curl https://evil-db.io/api/v1/cve/CVE-2022-2419