CVE Vulnerabilities

CVE-2022-26279

Direct Request ('Forced Browsing')

Published: Mar 24, 2022 | Modified: Aug 08, 2023
CVSS 3.x
9.8
CRITICAL
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CVSS 2.x
7.5 HIGH
AV:N/AC:L/Au:N/C:P/I:P/A:P
RedHat/V2
RedHat/V3
Ubuntu

EyouCMS v1.5.5 was discovered to have no access control in the component /data/sqldata.

Weakness

The web application does not adequately enforce appropriate authorization on all restricted URLs, scripts, or files.

Affected Software

Name Vendor Start Version End Version
Eyoucms Eyoucms 1.5.5 (including) 1.5.5 (including)

Potential Mitigations

References