CVE-2022-38305 AeroCMS v001 was discovered to contain an arbitrary file upload vulnerability via the component /admin/profilephp This vulnerability allows attackers to execute arbitrary code via a crafted PHP file authentication complexity vector not available not available not available confidentiality integrity availability not available not available no