Wisa Corp Smart Wing Cms vulnerabilities
2 known vulnerabilities affecting wisa_corp/smart_wing_cms.
Total CVEs
2
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL1HIGH1
Vulnerabilities
Page 1 of 1
CVE-2022-23770P2CRITICALCVSS 9.8≥ unspecified, < ver.190512022-10-17
CVE-2022-23770 [CRITICAL] CWE-20 CVE-2022-23770: This vulnerability could allow a remote attacker to execute remote commands with improper validation
This vulnerability could allow a remote attacker to execute remote commands with improper validation of parameters of certain API constructors. Remote attackers could use this vulnerability to execute malicious commands such as directory traversal.
nvd
CVE-2021-26639P3HIGHCVSS 7.5≥ unspecified, < r18715.202112292022-08-17
CVE-2021-26639 [HIGH] CWE-20 CVE-2021-26639: This vulnerability is caused by the lack of validation of input values for specific functions if WIS
This vulnerability is caused by the lack of validation of input values for specific functions if WISA Smart Wing CMS. Remote attackers can use this vulnerability to leak all files in the server without logging in system.
nvd