High severity7.2NVD Advisory· Published Oct 7, 2022· Updated Jun 17, 2026
CVE-2022-42092
CVE-2022-42092
Description
Backdrop CMS 1.22.0 has Unrestricted File Upload vulnerability via 'themes' that allows attackers to Remote Code Execution. Note: Third parties dispute this and argue that advanced permissions are required.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
backdrop/backdropPackagist | <= 1.22.0 | — |
Affected products
3- Backdrop CMS/Backdrop CMSdescription
- cpe:2.3:a:backdropcms:backdrop_cms:1.22.0:*:*:*:*:*:*:*
Patches
Vulnerability mechanics
References
3- grimthereaperteam.medium.com/backdrop-cms-1-22-0-unrestricted-file-upload-themes-ad42a599561cnvdExploitThird Party AdvisoryWEB
- github.com/advisories/GHSA-33c9-rppf-m7fqghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2022-42092ghsaADVISORY
News mentions
0No linked articles in our index yet.