Executive brief
SiteServer CMS is a web content management system used to build and manage websites. A vulnerability in the plugin functionality allows unauthenticated remote attackers to execute arbitrary code on the server, giving them complete control over the system, data, and hosted websites.
Technical details
SiteServer CMS versions 7.x and later contain a remote code execution vulnerability in the plugin function that allows attackers to execute arbitrary code by crafting and uploading a malicious plugin. The vulnerability requires no authentication or user interaction, as the plugin installation endpoint is network-accessible without proper authorization checks. An attacker can exploit this to gain full server-level permissions, leading to complete system compromise. The vulnerability was disclosed publicly in May 2022 and is tracked as CVE-2022-28118.
Affected products
- SiteServer CMS 7.x
Timeline
- 2022-05-02: disclosed
- 2022-05-04: advisory