OpenTeknik LLC OSSN OPEN SOURCE SOCIAL NETWORK v6.3 LTS was discovered to contain an arbitrary file upload vulnerability via the component /ossn/administrator/com_installer. This vulnerability allows attackers to execute arbitrary code via a crafted PHP file. Note: The project owner believes this is intended behavior of the application as it only allows authenticated admins to upload files.
{
"osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2022/34xxx/CVE-2022-34965.json",
"cna_assigner": "mitre",
"isDisputed": true
}{
"cpe": "cpe:2.3:a:openteknik:open_source_social_network:6.3:*:*:*:lts:*:*:*",
"source": [
"CPE_STRING",
"REFERENCES"
],
"extracted_events": [
{
"introduced": "6.3"
},
{
"last_affected": "6.3"
}
]
}