CVE-2022-3552
Unrestricted Upload of File with Dangerous Type in boxbilling/boxbilling
Vexday Risk Score
53Attention
SSVC decision (CISA)
Attend
PoC available → attend closely
CVSS 7.2EPSS 44.0%KEV nãoPoC públicaNuclei —Metasploit —Patch —
Lifecycle
17 Oct 2022Published on NVD
28 Mar 2023Public PoC
Recommendation: Plan a near-term fix — a public PoC already exists.
Unrestricted Upload of File with Dangerous Type in GitHub repository boxbilling/boxbilling prior to 0.0.1.
CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
Affected products
boxbilling · boxbilling/boxbillingpublic PoCs found — 4
githubgithub.com/0xk4b1r/CVE-2022-3552★ 8githubgithub.com/BakalMode/CVE-2022-3552★ 2cve_referencepacketstormsecurity.com/files/171542/BoxBilling-4.22.1.5-Remote-Code-Execution.htmlunverifiedexploitdbwww.exploit-db.com/exploits/51108unverified⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.
Want to know if your infrastructure is exposed to this?
Talk to TrueHacking →