CVE-2022-4136
Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
24/11/2022
Last modified:
30/11/2022
Description
Dangerous method exposed which can lead to RCE in qmpass/leadshop v1.4.15 allows an attacker to control the target host by calling any function in leadshop.php via the GET method.
Impact
Base Score 3.x
9.80
Severity 3.x
CRITICAL
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:a:leadshop:leadshop:1.4.15:*:*:*:*:*:*:* |
To consult the complete list of CPE names with products and versions, see this page



