CVE-2022-37190
30Vexday Risk Score
Patch soon. It has a working public exploit.
ssvc Attendepss 46%
exploitation probability
46%top 1% of all CVEs
observed exploitation
nono source reports it
CuppaCMS 1.0 is vulnerable to Remote Code Execution (RCE). An authenticated user can control both parameters (action and function) from "/api/index.php.
Affected products
n/a · n/a