Vulnerabilities > CVE-2022-26271 - Files or Directories Accessible to External Parties vulnerability in 74Cms 3.4.1

047910
CVSS 5.0 - MEDIUM
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
PARTIAL
Integrity impact
NONE
Availability impact
NONE
network
low complexity
74cms
CWE-552

Summary

74cmsSE v3.4.1 was discovered to contain an arbitrary file read vulnerability via the $url parameter at \index\controller\Download.php.

Vulnerable Configurations

Part Description Count
Application
74Cms
1