CVE-2022-37191
18Vexday Risk Score
Patch soon. It has a working public exploit.
ssvc Attendepss 3.6%
exploitation probability
3.6%top 11% of all CVEs
observed exploitation
nono source reports it
The component "cuppa/api/index.php" of CuppaCMS v1.0 is Vulnerable to LFI. An authenticated user can read system files via crafted POST request using [function] parameter value as LFI payload.
Affected products
n/a · n/a