6.5
CVSSv3

CVE-2022-37191

Published: 13/09/2022 Updated: 17/09/2022
CVSS v3 Base Score: 6.5 | Impact Score: 3.6 | Exploitability Score: 2.8
VMScore: 0

Vulnerability Summary

The component "cuppa/api/index.php" of CuppaCMS v1.0 is Vulnerable to LFI. An authenticated user can read system files via crafted POST request using [function] parameter value as LFI payload.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

cuppacms cuppacms 1.0