Miggo Logo

CVE-2022-46157:
Akeneo PIM Community Edition vulnerable to remote php code execution

8.8

CVSS Score
3.1

Basic Information

EPSS Score
0.50697%
Published
12/9/2022
Updated
1/28/2023
KEV Status
No
Technology
TechnologyPHP

Technical Details

CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Package NameEcosystemVulnerable VersionsFirst Patched Version
akeneo/pim-community-devcomposer>= 6.0.0, < 6.0.536.0.53
akeneo/pim-community-devcomposer< 5.0.1195.0.119

Vulnerability Intelligence
Miggo AIMiggo AI

Miggo AIRoot Cause Analysis:
In progress

WAF Protection Rules

WAF Rule

### Imp**t *k*n*o PIM *ommunity **ition v*rsions ***or* v*.*.*** *n* v*.*.** *llows r*mot* *ut**nti**t** us*rs to *x**ut* *r*itr*ry P*P *o** on t** s*rv*r *y uplo**in* * *r**t** im***. ### P*t***s *k*n*o PIM *ommunity **ition **t*r t** v*rsions **

Reasoning

No *n*lysis *v*il**l*