A local file inclusion (LFI) vulnerability in the component codemirror.php of Portal do Software Publico Brasileiro i3geo v7.0.5 allows attackers to execute arbitrary PHP code via a crafted HTTP request.
References
Link | Resource |
---|---|
https://github.com/wagnerdracha/ProofOfConcept/blob/main/i3geo_proof_of_concept.txt | Exploit Third Party Advisory |
https://owasp.org/www-project-web-security-testing-guide/v42/4-Web_Application_Security_Testing/07-Input_Validation_Testing/11.1-Testing_for_Local_File_Inclusion | Third Party Advisory |
Configurations
Information
Published : 2022-07-14 15:15
Updated : 2022-07-20 11:18
NVD link : CVE-2022-32409
Mitre link : CVE-2022-32409
JSON object : View
CWE
CWE-94
Improper Control of Generation of Code ('Code Injection')
Products Affected
softwarepublico
- i3geo