Critical severity9.8NVD Advisory· Published Feb 13, 2023· Updated Jun 17, 2026
CVE-2022-48323
CVE-2022-48323
Description
Sunlogin Sunflower Simplified (aka Sunflower Simple and Personal) 1.0.1.43315 is vulnerable to a path traversal issue. A remote and unauthenticated attacker can execute arbitrary programs on the victim host by sending a crafted HTTP request, as demonstrated by /check?cmd=ping../ followed by the pathname of the powershell.exe program.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
4- Sunlogin/Sunflower Simplifieddescription
- Range: 1.0.1.43315
- Range: 1.0.1.43315
Patches
Vulnerability mechanics
References
3- github.com/projectdiscovery/nuclei-templates/blob/8500efb7c5c52261229bb87b3af8a6e4e5afc877/cnvd/2022/CNVD-2022-03672.yamlnvdExploitThird Party Advisory
- www.cnvd.org.cn/flaw/show/CNVD-2022-03672nvdThird Party Advisory
- asec.ahnlab.com/en/47088/nvdTechnical Description
News mentions
0No linked articles in our index yet.